Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 09-26-2010, 06:49 PM
Junior Member
 
Posts: 9
Default Split Horizon DNS requirement

I am planning a full install of Zimbra to get ready for some testing and then hopefully migrating and moving to production. I have a question around the need to provide a split horizon or split brain DNS.

In our situation we leverage a third party (our ISP) to handle our public DNS queries and have only an internal DNS for our local lan. This DNS also cache's outside queries. I am able to have the third party DNS handle the MX records.

If I continue to leverage the third party DNS then I don't believe I need a split horizon DNS on the inside. Am I correct or is there something I am missing?
Reply With Quote
  #2 (permalink)  
Old 09-28-2010, 09:27 AM
Zimbra Consultant & Moderator
 
Posts: 20,317
Default

Quote:
Originally Posted by neontangerine View Post
Am I correct or is there something I am missing?
The answer to that is, it depends. If you are behind a NAT router or firewall then you will need a Split DNS set-up including a correct /etc/hosts file (details in the Quick Start Installation Guide).
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 09-28-2010, 07:50 PM
Junior Member
 
Posts: 9
Default

Quote:
Originally Posted by phoenix View Post
The answer to that is, it depends. If you are behind a NAT router or firewall then you will need a Split DNS set-up including a correct /etc/hosts file (details in the Quick Start Installation Guide).
Our firewall blocks DNS queries to our server and does provide NATing. The intention is to forward the SMTP port(s), leveraging SNAT and DNAT. We already run an internal DNS whereby several internal machines are available only from the inside.

If I query the Zimbra server (mail.domain.com) from internally by name I get the local address, if this is done from outside the firewall I get our public IP address as provided by the third-party DNS.

Functionally this is already split horizon is it not?

IS there something I am missing or need further?

Am I required to permit DNS queries to my IP?
Reply With Quote
  #4 (permalink)  
Old 09-29-2010, 06:32 AM
Zimbra Consultant & Moderator
 
Posts: 20,317
Default

Quote:
Originally Posted by neontangerine View Post
Our firewall blocks DNS queries to our server and does provide NATing. The intention is to forward the SMTP port(s), leveraging SNAT and DNAT. We already run an internal DNS whereby several internal machines are available only from the inside.

If I query the Zimbra server (mail.domain.com) from internally by name I get the local address, if this is done from outside the firewall I get our public IP address as provided by the third-party DNS.

Functionally this is already split horizon is it not?
Yes, it's a Split DNS set-up.

Quote:
Originally Posted by neontangerine View Post
IS there something I am missing or need further?
No, you shouldn't need anything else. Just for confirmation you can check the configuration in the 'Verify...' section of the Split DNS article in the wiki and see if it returns the correct output (also check the hosts file configuration).
__________________
Regards


Bill
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.