|
|
Question : DNS - Best practices regarding Dynamic Updates
|
|
Hello,
DNS in Windows Server have a setting for Dynamic Updates. The options are:
None Nonsecure and secure Secure only
I'd imagine that secure is the default and best option but am wondering why you would have a nonsecure setup and how the secure setting actually makes it 'secure'.
If a network is running Windows Server 2000 and 2003 with XP, Vista and Mac's then is secure the correct setting in this environment?
If nonsecure was required (for some reason) then is this really an issue if the internal network is secured by a firewall?
How does Secure ensure it is secure?
What other settings can help secure Windows DNS servers?
Thanks!
|
Answer : DNS - Best practices regarding Dynamic Updates
|
|
If you are talking about Active Direcory configuration, then SECURE transfers are recommended option, and additionally you may specify only particular IP's to transfer zones to. Here are some readings on the subject: http://www.windowsecurity.com/articles/Securing_windows_2000_DNS_by_using_configuration_Part_2.html
|
|
|
|