How to allow external resolution for a certain domain ONLY?


hi all,

i'm changing our internet access infrastructure , have hit upon bit on issue. security reasons, not allow our internal clients resolve external addresses @ all, servers need can (via caching proxy has forwarder internal addresses). 

however, use zscaler , need use zscaler 'road warriors' (users company laptops outside corporate network. making use of pac file, hosted @ zscaler. means when internal need access file well.

in short pac.zscaler.net must resolvable @ times, no other external addresses must available resolve when internal.

what have done created new primary zone on our ad servers 'pac.zscaler.net' , added blank record ip address server... zscaler provides 20 ip addresses pac file location. 

can add 20 different ip addresses primary zone 'pac.zscaler.com' on internal network? if so, how clients pick ip address resolve to? round robin? 

thanks help! 

hi miguel,

thanks response, unfortunately constraint our ad servers not allowed go external zone transfers, automatic out. luckily zscaler publishes list , notifys customers time ips change, while it's annoying, manual process work quite well.

what have done not created zone zscaler.net (otherwise think if don't have entry 'admin.zscaler.net' won't able access management page). created zone 'pac.zscaler.net' add records no name. in practice works resolving 'pac.zscaler.net' in round robin fashion ip addresses add there. mean

pac.zscaler.net has 4 ips (made ips example)

192.168.0.1

192.168.0.100

192.168.0.106

192.168.0.199

if nslookups internally against 'pac.zscaler.net' resolve each of addresses in turn.

i think contraint internal ad servers not allowed out past firewall, seems best way achieve this.



Windows Server  >  Network Infrastructure Servers



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group