Split-DNS on ISR routers

Started by LynK, March 02, 2016, 02:34:27 PM

Previous topic - Next topic

LynK

hey guys,

has anyone installed SPLIT-DNS on their ISR 2800/2900's? Did you come into any issues with it not functioning properly?
Sys Admin: "You have a stuck route"
            Me: "You have an incorrect Default Gateway"

Reggle

A bit off topic perhaps, but I would *never* run DNS on a Cisco router. Whatever the plan, there has to be a better design.

deanwebb

Lolz... and Cisco bought OpenDNS.
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

LynK

which is exactly why we need to use split DNS.

We have PBR with external IP going out cable connection. The issue is the internal hosts are pointing to internal DNS servers. So when they go to playboy.com it queries internal DNS and then sends the traffic out the cable connection unfiltered.

yeah.. thats an issue.

So this is why we need split-dns on the router. send external to OpenDNS. Send internal to internal DNS.
Sys Admin: "You have a stuck route"
            Me: "You have an incorrect Default Gateway"

icecream-guy

Quote from: LynK on March 03, 2016, 08:33:38 AM
which is exactly why we need to use split DNS.

We have PBR with external IP going out cable connection. The issue is the internal hosts are pointing to internal DNS servers. So when they go to playboy.com it queries internal DNS and then sends the traffic out the cable connection unfiltered.

yeah.. thats an issue.

So this is why we need split-dns on the router. send external to OpenDNS. Send internal to internal DNS.
.
:professorcat:

My Moral Fibers have been cut.

Otanx

I'm not following. So you have an internal DNS server, and it does look-ups external. So just configure that internal DNS to send requests to OpenDNS.

-Otanx

LynK

no bueno. haha because we use the same internal DNS servers here at HQ.

it is kind of confusing. If anyone needs a decent PBR/split-dns solution down the road hit me up.
Sys Admin: "You have a stuck route"
            Me: "You have an incorrect Default Gateway"