<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: DNS Related Performance Problems for the ISA Firewall</title>
	<link>http://blogs.isaserver.org/shinder/2006/05/08/dns-related-performance-problems-for-the-isa-firewall/</link>
	<description>Written by Dr Thomas W Shinder, consultant to Microsoft, HP and many Fortune 500 companies on ISA firewall and Web proxy deployments this blog is where administrators get information about ISA Server Universal Threat Management firewalls. Topics include how to manage, deploy, and troubleshoot ISA Server as a network firewall, Web proxy/Web cache, remote access VPN server and VPN gateway to provide a high level of network security for all corporate computers.</description>
	<pubDate>Fri, 29 Aug 2008 17:21:40 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: Jaired Anderson</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/08/dns-related-performance-problems-for-the-isa-firewall/#comment-124516</link>
		<pubDate>Mon, 15 Oct 2007 19:57:50 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/08/dns-related-performance-problems-for-the-isa-firewall/#comment-124516</guid>
					<description>Tom-

How could one determine if DNS is the performance robbing culprit if one is configured in cache mode only? (forward proxy).

Thanks.</description>
		<content:encoded><![CDATA[<p>Tom-</p>
<p>How could one determine if DNS is the performance robbing culprit if one is configured in cache mode only? (forward proxy).</p>
<p>Thanks.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Thomas Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/08/dns-related-performance-problems-for-the-isa-firewall/#comment-688</link>
		<pubDate>Thu, 11 May 2006 12:30:47 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/08/dns-related-performance-problems-for-the-isa-firewall/#comment-688</guid>
					<description>Hi Don,
You bet!
Thanks!
Tom</description>
		<content:encoded><![CDATA[<p>Hi Don,<br />
You bet!<br />
Thanks!<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: DonMurphy</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/08/dns-related-performance-problems-for-the-isa-firewall/#comment-687</link>
		<pubDate>Thu, 11 May 2006 04:41:24 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/08/dns-related-performance-problems-for-the-isa-firewall/#comment-687</guid>
					<description>Thanks for the clarification</description>
		<content:encoded><![CDATA[<p>Thanks for the clarification
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Thomas Shinder Blog &#187; Blog Archive &#187; General Approach to Solving Performance Issues with the ISA Firewall Part 1</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/08/dns-related-performance-problems-for-the-isa-firewall/#comment-684</link>
		<pubDate>Tue, 09 May 2006 11:47:58 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/08/dns-related-performance-problems-for-the-isa-firewall/#comment-684</guid>
					<description>[...] If PMTU and black hole routers are ruled out as a problem, then check the DNS settings on the ISA firewall&amp;#8217;s NICs. I discussed that in my last post, which you can read at http://blogs.isaserver.org/shinder/2006/05/08/dns-...ewall/ [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] If PMTU and black hole routers are ruled out as a problem, then check the DNS settings on the ISA firewall&rsquo;s NICs. I discussed that in my last post, which you can read at <a href='http://blogs.isaserver.org/shinder/2006/05/08/dns-&#8230;ewall/' rel='nofollow'>http://blogs.isaserver.org/shinder/2006/05/08/dns-...ewall/</a> [&#8230;]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Thomas Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/08/dns-related-performance-problems-for-the-isa-firewall/#comment-683</link>
		<pubDate>Tue, 09 May 2006 11:06:00 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/08/dns-related-performance-problems-for-the-isa-firewall/#comment-683</guid>
					<description>Hi Don,

There's really no reason to do this, and it could slow things down just a bit. If the first adapter query fails, there no reason to deal with waiting for the second adapter query to fail since its the same DNS server. Just remove DNS settings from all interfaces except the internal interface.
HTH,
Tom</description>
		<content:encoded><![CDATA[<p>Hi Don,</p>
<p>There&#8217;s really no reason to do this, and it could slow things down just a bit. If the first adapter query fails, there no reason to deal with waiting for the second adapter query to fail since its the same DNS server. Just remove DNS settings from all interfaces except the internal interface.<br />
HTH,<br />
Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: DonMurphy</title>
		<link>http://blogs.isaserver.org/shinder/2006/05/08/dns-related-performance-problems-for-the-isa-firewall/#comment-682</link>
		<pubDate>Tue, 09 May 2006 05:00:47 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/05/08/dns-related-performance-problems-for-the-isa-firewall/#comment-682</guid>
					<description>Hey Tom.  Great stuff as usual.  

In a 2 nic simple SBS premium config we usually specify the dns settings of our internal LAN to ourselve (which is in SBS lingo the DNS server).  We agree so far.  But what we also do is on the external interface we point the dns server to the internal lan NIC as well.  Do you see anything wrong with this approach?</description>
		<content:encoded><![CDATA[<p>Hey Tom.  Great stuff as usual.  </p>
<p>In a 2 nic simple SBS premium config we usually specify the dns settings of our internal LAN to ourselve (which is in SBS lingo the DNS server).  We agree so far.  But what we also do is on the external interface we point the dns server to the internal lan NIC as well.  Do you see anything wrong with this approach?
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
