Home > Ask the Information Security Experts > Secure software development and application/platform security Questions & Answers > Windows 2003 DNS configuration tips
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

Windows 2003 DNS configuration tips

>
QUESTION:
I have a Windows 2003 DNS as our main DNS server, which is the authoritative server for our domain. If I stop recursion on this server, no one can get to the Internet as it doesn't resolve anything. Can you please advise me on how to resolve these Windows 2003 DNS configuration issues?


RELATED CONTENT
Secure software development and application/platform security
How to protect a laptop from spam, viruses
What is the best choice for an enterprise Web browser?
How to detect and remove Sinowal and repair a master boot record
How does search engine malware spread?
How effective are password hack tools?
How do attackers use Google to hack?
Why does Google have the right to block virus-infected websites?
Should a worm patch or push security updates?
How to find and prevent SQL injection attack vulnerabilities

Platform and OS Security Management
Microsoft issues advisory on new IE security vulnerability
Microsoft patches SMB flaws, Hyper-V problem in big update
Microsoft blue screen affecting few corporate PCs
Microsoft to fix 26 flaws in Windows, Office
Thin-client technologies surge thanks to easier security, says Deloitte
Microsoft issues critical security update, blocks IE 6 attacks
How to use Windows XP Mode in Windows 7
Microsoft to patch single Windows 2000 vulnerability
How to prevent memory dump attacks
Microsoft gives Internet Explorer a major security overhaul

Endpoint and NAC Protection
How to prevent iPhone spying: mobile phone management tips
Considering two-factor authentication? Do cost, risk analysis
Look into SIEM services to cut costs, comply with PCI DSS, HIPAA
Voice data security risks on the rise, say experts
The value of booting from a VHD in Windows 7
Thin-client technologies surge thanks to easier security, says Deloitte
A closer look at Internet Explorer 8 security features
USB drive security best practices and processes
First step in forensics: Create a bootable Windows environment CD
Protecting enterprise networks from new mobile application downloads

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Serious Organized Crime Agency  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Richard Brain EXPERT RESPONSE FROM: Richard Brain

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site
ANSWERED October 2009:
I would advise instead that layered security is implemented, which allows no direct outbound client connections to the Internet. This arrangement prevents malware from spreading or communicating by opening arbitrary outbound ports to the Internet. The Web browsers are pointed to a Web proxy within a DMZ, and the proxy will handle the DNS server resolution separately to the Windows server.

Alternatively, you can configure your server's DNS to forward requests to your ISP's server, though you open yourself to cache poisoning attacks if your ISP's servers become subverted.

If no forwarders are configured, the DNS server will use root hints, which contain host information necessary to resolve names outside of the authoritative DNS domains. The process is slower, but safer.




Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Access Management: Authentication, Biometrics, Password Security
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts