Local DNS in the cloud era

68 views
Skip to first unread message

Simon Wright

unread,
Jul 20, 2026, 7:57:09 PM (11 days ago) Jul 20
to techies-f...@googlegroups.com
I feel I'm over thinking this, but as 99.9% of client devices are now fully azure/entra connected.
I've migrated some random services and name resolution to Cloudflare.

But I still want/require? local DNS and I'm not completely sure why...
The only thing I can immediately think of is that we are still going to need an onsite print server with Papercut. I'm looking at building a new one on server 2025 so it can be entra managed rather than local AD connected, still looking into this as I believe 2025 allows auth/security via entra so teacher devices should be able to install/connect to the print queues with no AD.

What am I missing or am I overthinking this? My old school Windows NT era mindset can't let go.

For those who no longer have local AD infrastructure, are you just winging it with external dns?


Simon.


DISCLAIMER
This e-mail is intended for the addressee only and may contain information which is subject to legal privilege. This e-mail message and accompanying data may contain information that is confidential and subject to privilege. Its contents are not necessarily the official view Otago Boys’ High School or communication of the Otago Boys’ High School. If you are not the intended recipient you must not use, disclose, copy or distribute this e-mail or any information in, or attached to it. If you have received this e-mail in error, please contact the sender immediately or return the original message to Otago Boys’ High School by e-mail, and destroy any copies. Otago Boys’ High School does not accept any liability for changes made to this e-mail or attachments after sending.

Clayton Hubbard

unread,
Jul 20, 2026, 8:15:27 PM (11 days ago) Jul 20
to techies-f...@googlegroups.com
Hi Simon,

Depends how sophisticated you need but a number of schools just have their local DNS entries on the firewall and then that proxies to external if not a local request.

1. Make sure the search domain is set
2. Implement local entries for that local domain
3. Everything else goes out.
4. Point primary dns to the firewall. (Normally quicker and efficient because it can also cache

Cheers,

Clayton Hubbard
Principal Advisor - Digital Futures


--
You received this message because you are subscribed to the Google Groups "Techies for schools" group.
To unsubscribe from this group and stop receiving emails from it, send an email to techies-for-sch...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/techies-for-schools/CAEJps9r0hZP49H%3DK8mMbseJ9r2tmOfBED4sMv14ANhh_cho0BQ%40mail.gmail.com.

DISCLAIMER:
This email, including attachments, may contain information which is confidential or privileged material. If you are not the intended recipient, please notify us immediately and then delete this email from your system. Email communications are not secure and are not guaranteed by The Network for Learning to be free of unauthorised interference, error or virus. Anyone who communicates with us by email is taken to accept this risk. Anything in this email which does not relate to the official business of The Network for Learning is neither given nor endorsed by The Network for Learning.

Simon Wright

unread,
Jul 20, 2026, 8:21:55 PM (11 days ago) Jul 20
to techies-f...@googlegroups.com
Thanks Clayton,

I've already put in a case to ask the question about migrating dns to the firewall, which is ideally what i'd like.
Now that we have the Palo Alto box i assume this is a lot easier as i do remember asking this question some time ago with the Fortigate but Spark didn't want to allow that from what i was originally told.

I've got a printer/copier renewal coming up soon so i want those to have a new dns address rather than the AD one.

Simon.


d.keen...@gc.ac.nz

unread,
Jul 20, 2026, 9:15:07 PM (11 days ago) Jul 20
to Techies for schools
Just a few things that pop to mind:
1) Local DNS is precisely that, readable by your local systems.  You may have entries you do not want the Public/AI to know about; like what can be targeted.
2) Sometimes tunnelling systems are in use; you may want a public version of the IP for the tunnel and the internal IP otherwise; very useful with NetBird and Zerotier.
3) DNS caching really does speed things up.  And, if you want your own control, a couple of PiHole VMs can work wonders for filtering and load-balancing; very powerful.

Regards,

David Keenleyside, BSc CS & IS, CTech

ITP Associate

EFF Member

ICT Technician

Glenfield College

PO Box 40176 (Kaipatiki Rd)

Glenfield, Auckland City 0629


Ph:       +64 9 444 9066 ext 677

DDI: +64 9 441 9779

Email:    d.keen...@gc.ac.nz

https://itp.nz/CTech/NZ160799

https://www.linkedin.com/in/david-keenleyside-626871/

The Three O’s of Backup: Online, Offline, Off-site.

The Three RA’s of Cloud: Run Anywhere, Run Anytime, Run Agnostic.

“When you're working as part of a team, one of the things to expect is that you should share information freely with your colleagues and that they'll share information freely with you.” - Google


Reply all
Reply to author
Forward
0 new messages