[Shorewall-users] DNS Advice plz

Tarax cerbere at arkitekts.org
Thu, 10 Oct 2002 13:59:09 +0200


Hi all,

Brand new to the list, I first would like to congratulate and thank you T=
om=20
for the GREAT PIECE OF SOFTWARE you provide us with, and the DOCUMENTATIO=
N=20
EFFORT you made. If all projects had this kind of support, linux counter=20
would have exploded !!!

<note>
It would be a pleasure to make a french translation, I'll think about tha=
t and=20
have a glimpse to my planning up to Xmas....
</note>

   I run a 4 Linux Mandrake 9.0 boxes network:=20
=09- 1 Firewall (static IP on ppp0 through eth0 - 172.16.0.1),
=09- 1 Sever (I'd like to be DMZed - in 10.10.0.0/24), tending to become =
a=20
subnet of "One service Boxes", for www, mail, ftp, mysql, ...
=09- 1 Workstattion & 1 Laptop (local zone - 192.168.0.0/24).
   I also would like to be able to access all my boxes from my laptop whe=
n I'm=20
on the road.
   I've read the doc's, many times the 3-interfaces guide & Tom's config,=
 and=20
had a look at different (of the numerous !) threads about DNS issues in t=
his=20
list archive.
   All that done, I can't figure what's the best choice (ease of setup, c=
onf.=20
flexibility) for DNS setup between:
=09- running it on the FW or in the DMZ ?
=09- running two DNS, one on the FW & one in the DMZ ?

   All advices & tips will be greatly appreciated, as well as sample DNS=20
configuration files for a simple setup like mine, a complete network setu=
p=20
tutorial (involving all services listed above) is on the way & will be GP=
Led=20
as soon as first steps will be written and cleaned.

  Once again thank you Tom for your work and time devotion. I'am always=20
pleased to join another community, reading the list archive I've no doubt=
=20
this one will be another good one ! ;-)
   Waiting for your answers, I go back to the docs to glean pieces of inf=
o I'd=20
have missed...

J=E9r=E9mie

--=20
Future Is Free, Fight Against Bill & Friends
Linux User # 274160
Linux Boxes #157052, 157053, 157054
MandrakeClub Member