On Tuesday, February 06, 2007 8:49 PM +1300 Jason Haar <[EMAIL PROTECTED]> wrote:

Hmm - I would assume the opposite. Most people would run SA in DMZes
wouldn't they? And most DMZ design philosophies are that DMZ hosts
should attempt to have near-zero access to internal resources. i.e. no
internal DNS.

Why would you be sending internal domain names through your external SA? If you send to another internal user who might use a VPN from outside, you still send to his internal address.


Reply via email to