This is just asking for trouble. Internal clients should not use an external DNS server for name resolution if at all possible. A split DNS system should be used instead, where the internal DNS servers use the same domain name but serve up the internal IP address.

External DNS servers, being external, are subject to way too much potential abuse such as cache poisoning.

Ray

A common scenario where you would use DNS doctoring is when you have a Public server on a DMZ and you would like for the machines on the internal network to be able to access it using it's domain name, but using an external DNS for the resolution, which off course resolves a public IP address.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to