<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: About Split DNS</title>
	<link>http://blogs.isaserver.org/shinder/2006/11/04/about-split-dns/</link>
	<description>Written by Dr Thomas W Shinder, consultant to Microsoft, HP and many Fortune 500 companies on ISA firewall and Web proxy deployments this blog is where administrators get information about ISA Server Universal Threat Management firewalls. Topics include how to manage, deploy, and troubleshoot ISA Server as a network firewall, Web proxy/Web cache, remote access VPN server and VPN gateway to provide a high level of network security for all corporate computers.</description>
	<pubDate>Thu,  4 Dec 2008 21:26:45 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: AFlowers</title>
		<link>http://blogs.isaserver.org/shinder/2006/11/04/about-split-dns/#comment-57934</link>
		<pubDate>Thu, 11 Jan 2007 14:03:25 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2006/11/04/about-split-dns/#comment-57934</guid>
					<description>I too have been investigating the use of a split DNS within our organization, and have similarly set up a test bed.  My test bed used the firewall's NAT and DNS functions to serve as the external DNS server.  My internal DNS service is hosted on the AD domain controller.  Everything works!  I can't find any problems - security holes - with this approach.  Are there any security holes? 

Related question: Would this approach eliminate the need for an internal domain (int.abc.com) with a separate name from the external domain (abc.com)?</description>
		<content:encoded><![CDATA[<p>I too have been investigating the use of a split DNS within our organization, and have similarly set up a test bed.  My test bed used the firewall&#8217;s NAT and DNS functions to serve as the external DNS server.  My internal DNS service is hosted on the AD domain controller.  Everything works!  I can&#8217;t find any problems - security holes - with this approach.  Are there any security holes? </p>
<p>Related question: Would this approach eliminate the need for an internal domain (int.abc.com) with a separate name from the external domain (abc.com)?
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
