← Back to Book Detail

24 Domain Name System Part 2 – Forwarding DNS (24/26) -- Mastering Enterprise Networks

Browse
92%

24 Domain Name System Part 2 – Forwarding DNS

24 Domain Name System Part 2 – Forwarding DNS Jacob Christensen In the last lab, we configured our network so our devices could communicate via human-readable names rather than IP addresses. However, we did not build the ability to interact with Internet domains. In this chapter, we will reconfigure our DNS server to forward non-authoritative domain queries (such as www.google.com) to a public resolver and further extend our network’s capabilities. Estimated time for completion: 25 minutes Learning Objectives - Demonstrate how to configure and implement a forwarding DNS server for Internet communications - Learn how to implement a network address translation (NAT) rule between a LAN and WAN Prerequisites Deliverables - Screenshot of RED1 - Successful nslookup of Google - Successful ping of Google - Screenshot of BLUE1 - Successful nslookup of Google - Successful ping of Google - Screenshot of the dig trace of Google - Screenshot of GNS3 environment Resources - BIND9 Administrator Reference Manual – https://bind9.readthedocs.io/en/v9.18.16/ - MikroTik RouterOS Documentation – https://help.mikrotik.com/docs/display/ROS/RouterOS Contributors and Testers - Mathew J. Heath Van Horn, PhD, ERAU-Prescott - Kyle Wheaton, Cybersecurity Student, ERAU-Prescott DNS Hierarchy Explained When you look up a website for the first time, you may notice it will load considerably slower when compared to subsequent revisits. This is because your computer does not yet know the web server’s IP address, and must ask around first before it can start making HTTP requests. However, once the domain-to-IP translation is known, various entities such as your browser, computer, router, and ISP servers all have local storage reserved for caching this information, which speeds up query resolutions. This is a feature for end-user convenience and saving bandwidth, but how does your DNS server know where to look when it receives an unknown domain? Reference the diagram below while you follow these steps to understand the process. 1. The client device makes a DNS query to the LAN’s server for the domain <erau.edu.> 2. The domain is neither cached nor listed under any of its zones, so it forwards the request to a DNS resolver 3. The Resolver has a built-in list of all of the root DNS servers - There are 13 root <.> servers in the world. They are named sequentially from <a.root-servers.net> to <m.root-servers.net> - Each one knows the location of the Top Level Domain (TLD) servers 4. One of the root servers will provide the address of the <edu> TLD server, which is sent back to the Resolver 5. The Resolver will query the <edu> TLD server for the <erau> subdomain 6. The subdomain DNS identifies the webserver for <erau.edu.> and sends this information back to the end user Now that we understand how a Forwarding DNS server works, let’s build one for our network. Phase I – Building Network Topology This lab is an extension of Chapter 23. If you have not completed it yet, it is recommended th
← Previous Chapter Next Chapter →