Paul,

Sorry for the late comments.

A question to your draft:

Introduction:

Is "Split DNS" less about "configuration for the secure tunnels", but more 
about having two zones, one to be used by the internal network, the other used 
by the external network?
Basically Split DNS directs internal hosts to an internal domain name server 
for name resolution and external hosts are directed to an external domain name 
server for name resolution.

Is it correct? If yes, the requests from internal network (the network within 
VPN) may not be via tunnel, isn't it?

Or your "split DNS" is about one DNS with some domain name resolution requests 
are from IPSec tunnels and others are not?


Linda

-----Original Message-----
From: IPsec [mailto:[email protected]] On Behalf Of Paul Wouters
Sent: Monday, January 22, 2018 12:49 PM
To: [email protected] WG <[email protected]>
Subject: Re: [IPsec] I-D Action: draft-ietf-ipsecme-split-dns-04.txt

On Mon, 22 Jan 2018, [email protected]<mailto:[email protected]> 
wrote:

> Subject: [IPsec] I-D Action: draft-ietf-ipsecme-split-dns-04.txt

> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-ipsecme-split-dns-04

This version addresses the two points raised by Paul Hoffman.

I believe this document is ready for IETF LC.

Paul

_______________________________________________
IPsec mailing list
[email protected]<mailto:[email protected]>
https://www.ietf.org/mailman/listinfo/ipsec

_______________________________________________
IPsec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipsec

Reply via email to