Windows – Allow internal DNS to be queried from the DMZ

dmzdomain-name-systemnetworkingSecuritywindows

We have a mail gateway running in a DMZ, which is a relay for our internal mail server holding all the mail. We have come accross the need to use DNS from the DMZ to resolve names of internal services (such as the internal mail server, etc.).

Should we allow DNS queries from the DMZ to LAN? This would result in a serious breach in case some of the DMZ servers were compromised. On the other hand, not allowing the DNS queries makes us much less flexible.

I came accross the concept of a split-brain DNS, which is, I assume, what would solve the problem, but I do not quite understand how it can be accomplished in a Windows AD integrated environment.

Best Answer

Complete the hosts file on the mail gateway server with the servers you would have wanted to resolve by DNS.