Subscribe to Windows IT Pro
March 27, 2008 12:00 AM

A Sysadmin’s DNS Best Practices

Windows IT Pro
InstantDoc ID #98331
Rating: (1)

  1. Create DNS zones in internal DNS servers to fight some obvious Web ads.
  2. Use OpenDNS (www.opendns.com) DNS servers as forwarders, to add an extra layer of security.
  3. Block the exact DNS protocols (UDP, TCP, or both) on the edge—the firewall—and on the server. Also, lock down the DNS server. I’ve found Windows Server 2003 SP1’s security configuration wizard very useful for these two tasks.
  4. Use Active Directory (AD)–integrated zones and secure dynamic updates.
  5. Restrict DNS replication only to the necessary DNS servers.
  6. Implement split DNS, if applicable.
  7. Use DNSstuff (www.dnsstuff.com) to get useful additional information—also helpful for troubleshooting.
  8. Get rid of NetBIOS over TCP and WINS. (Windows Server 2008 has a special DNS zone that eliminates the need for a WINS server.)
  9. Develop your own best practices list!

Related Content:

ARTICLE TOOLS

Comments
  • Abby
    4 years ago
    Mar 27, 2008

    This is very helpful. I did not know about this and will make the changes ASAP!.

    Thank you.

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.