Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Internal DNS and gateway ip/ipx

0 views
Skip to first unread message

kvictor

unread,
Nov 17, 2000, 3:00:00 AM11/17/00
to
Hi all,

My network has internal DNS and WEB. Users use Gateway IP/IPX (Border
Manager 2.1) for Internet. They must turn off it if want to work with
our DNS and WEB. It is very inconveniently. Can I adjust my BM for
work with my DNS/WEB and Gateway together without switching off it?

Regards Victor.

* Sent from Novell Discussion Forums http://novell.remarq.com The Internet's Discussion Network *
The fastest and easiest way to search and participate in Usenet - Free!


Craig Johnson

unread,
Nov 17, 2000, 3:00:00 AM11/17/00
to
First of all, do you point the BMgr server at the internal DNS server
for the first DNS server in the sys:etc\resolv.cfg file?

Have you considered moving off of the IPX/IP Gateway altogether? It is
not really needed, and it causes a number of problems, not just what
you have mentioned.

Craig Johnson
Novell Support Connection SysOp
(See http://nscsysop.hypermart.net for BorderManager hints, tips and
files, as well as books on configuring BorderManager.)


kvictor

unread,
Nov 17, 2000, 3:00:00 AM11/17/00
to
No, the resolve.cfg file has not the internal DNS server. It keeps only
the DNS of my internet provider.
To remove GW I cannot because have many users with IPX. Plus, GW gives
me the complete access controll than NAT.

Terry Rodecker

unread,
Nov 19, 2000, 3:00:00 AM11/19/00
to
Hi,

> No, the resolve.cfg file has not the internal DNS server. It keeps only
> the DNS of my internet provider.

Then you'll need to enter in the DNS addresses of your internal DNS
servers. Here's why. When workstations use either the IPX/IP or the
IP/IP gateways, all their IP communications come from the gateway server
(in this case, the BM server). As such, if your users want to use DNS
names for internal resources, you'll need to have the gateway server be
able to resolve those DNS names.

There is another way to handle it but it's not as elegant. You can add
the internal records into your BM server's SYS:ETC\HOSTS file. The
drawback there is it would be a manual process to update that file
whereas adding the internal DNS servers to your SYS:ETC\RESOLV.CFG file
would be automatic.

> To remove GW I cannot because have many users with IPX. Plus, GW gives
> me the complete access controll than NAT.

If your users only have IPX bound then the IPX/IP gateway would be a
necessity. However, you can still get most of the control (all of it if
all you do is browse the Internet) using the proxy server. If you plan
on upgrading to BM 4.0 when it comes out, you'll have to be off the
IPX/IP gateway anyway as I do believe it's been dropped in that version.

--
Terry Rodecker
Novell Support Connection Volunteer SysOp
Using VA 5.50 build 311

kvictor

unread,
Nov 20, 2000, 3:00:00 AM11/20/00
to
Hi Terry,

I tried to set a record of my internal DNS in BM and to use the
dynamic NAT in my test network . NAT works well, but DNS is badly.
Whether I need in some adjusting of my DNS and BM for this. My DNS
server is NW5.1 with SP1.

Regards Victor.

Terry Rodecker

unread,
Nov 20, 2000, 3:00:00 AM11/20/00
to
> but DNS is badly.
> Whether I need in some adjusting of my DNS and BM for this.

Where did you add it in? If it isn't first on the list, then your
BorderManager server has to wait for the other configured DNS servers
to come back and say "we don't know where this host is" before it
finally gets to the Internal DNS server where it can get the right IP
address. You might want to configure your internal DNS server as the
first in the list and see if that improves performance any at all, at
least for the internal sites.

Terry Rodecker

unread,
Nov 25, 2000, 3:00:00 AM11/25/00
to
Sorry for taking a while to get back to you. I seem to have lost track
of this thread.

Just to make sure there's nothing else happening here, add a record in
your BM server's SYS:ETC\HOSTS file for your internal server then try
to access it and let me know what happens.

0 new messages