Re: [Freeipa-users] DNS configuration for not resolving some addresses

2015-07-13 Thread Petr Spacek
On 8.7.2015 20:46, Karl Forner wrote: I forgot my main use case: I have name-based reverse proxies (SNI) for some web apps/services , that are accessible both from the internal and external network. They must be accessed with the exact same name/url, otherwise the dispatch can not work.

Re: [Freeipa-users] DNS configuration for not resolving some addresses

2015-07-08 Thread Jan Pazdziora
On Wed, Jul 08, 2015 at 02:26:02PM +0200, Karl Forner wrote: When using my freeIPA DNS name server for my domain example.test, I need to exclude some names from the server( to be forwarded to the DNS forwarder for instance. For example, I'd like foo.example.test not to be resolved, but

Re: [Freeipa-users] DNS configuration for not resolving some addresses

2015-07-08 Thread Karl Forner
On Wed, Jul 8, 2015 at 2:32 PM, Jan Pazdziora jpazdzi...@redhat.com wrote: On Wed, Jul 08, 2015 at 02:26:02PM +0200, Karl Forner wrote: When using my freeIPA DNS name server for my domain example.test, I need to exclude some names from the server( to be forwarded to the DNS forwarder

Re: [Freeipa-users] DNS configuration for not resolving some addresses

2015-07-08 Thread Karl Forner
Okay, but DNS doesn't work in that way. Zone example.test. is authoritative, so it must contain the record or delegation or NXDOMAIN is returned. You cannot have multiple authoritative copies of one zone with different data. The best solution would be to have only internal.example.test. zone

Re: [Freeipa-users] DNS configuration for not resolving some addresses

2015-07-08 Thread Karl Forner
Thanks Petr. My use case is: we have scripts that connect to some services, let's say a docker registry. I want these scripts to be work either internally or externally, without changing the URLs. What would the best or easiest setting to achieve this ? On Wed, Jul 8, 2015 at 4:25 PM, Petr

Re: [Freeipa-users] DNS configuration for not resolving some addresses

2015-07-08 Thread Petr Spacek
On 8.7.2015 16:32, Karl Forner wrote: Thanks Petr. My use case is: we have scripts that connect to some services, let's say a docker registry. I want these scripts to be work either internally or externally, without changing the URLs. What would the best or easiest setting to achieve this

Re: [Freeipa-users] DNS configuration for not resolving some addresses

2015-07-08 Thread Karl Forner
Thanks Martin, but I do not want to forward the whole subzone. I have the example.test zone from my web hosting site, that manages also the domain example.test I use the example.test domain in freeIPA. So the problem is that in the internal network, I can no longer resolve www.example.test. Of

Re: [Freeipa-users] DNS configuration for not resolving some addresses

2015-07-08 Thread Martin Basti
On 08/07/15 16:14, Karl Forner wrote: Thanks Martin, but I do not want to forward the whole subzone. I have the example.test zone from my web hosting site, that manages also the domain example.test I use the example.test domain in freeIPA. So the problem is that in the internal network, I can

Re: [Freeipa-users] DNS configuration for not resolving some addresses

2015-07-08 Thread Petr Spacek
On 8.7.2015 15:07, Karl Forner wrote: On Wed, Jul 8, 2015 at 2:32 PM, Jan Pazdziora jpazdzi...@redhat.com wrote: On Wed, Jul 08, 2015 at 02:26:02PM +0200, Karl Forner wrote: When using my freeIPA DNS name server for my domain example.test, I need to exclude some names from the server( to

Re: [Freeipa-users] DNS configuration for not resolving some addresses

2015-07-08 Thread Karl Forner
I forgot my main use case: I have name-based reverse proxies (SNI) for some web apps/services , that are accessible both from the internal and external network. They must be accessed with the exact same name/url, otherwise the dispatch can not work. Until now I manage this by manually editing all