BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Using public DNS for intranet hosts?
- Subject: [Discuss] Using public DNS for intranet hosts?
- From: dsr at randomstring.org (Dan Ritter)
- Date: Sat, 29 Aug 2026 14:30:42 -0400
- In-reply-to: <27283.2765.274121.58032@gargle.gargle.HOWL>
- References: <mailman.1.1788019202.28900.discuss@lists.blu.org> <27283.2765.274121.58032@gargle.gargle.HOWL>
Daniel Barrett wrote: > Rich Pieri <richard.pieri at gmail.com> wrote: > >On Fri, 28 Aug 2026 15:42:05 -0400 Daniel Barrett <dbarrett at > >blazemonger.com> wrote: > > Thanks. I'm curious, is it a "bad idea" just because it's an ugly > hack, or is there another reason? (FWIW, I ran a test, and my > registrar's DNS software accepts an A record of this sort without any > complaint, and tech support told me it doesn't seem to violate any of > their policies.) It's the sort of thing which gets an organization with more than one sysadmin in trouble. You can do this, if you really want to. > >The correct solution is to run a little caching nameserver inside your > >private network and put your private records here. > > I totally agree, and that would be a great suggestion if I were not > the only person with sysadmin skills in my household, but I am. I > can't have non-spouse-compatible solutions in place, like a headless > Raspberry Pi in the basement, that nobody else can maintain if I die > or am unavailable. That's why I mentioned my spouse in my original > post. Are you sure you're not falling prey to https://xkcd.com/2501/ ? My kids (college-age plus) vaguely know what DNS is, but I don't think they'd get around to diagnosing a problem as "the DNS server isn't responding". My spouse, on the other hand, has led large and small ISP customer support teams, and ... might think about it, but probably not. > Any alternative suggestions/feedback? Thank you very much. Wall of descriptive text incoming, you have been warned. The house router is a headless, fanless microPC -- pretty similar to this one: https://www.amazon.com/Sharevdi-Fanless-Firewall-Ethernet-Gigabit/dp/B0F7XMZC1D It runs Debian stable, and beyond being a firewall/router, it runs: - ntp - a dynamic DNS client - WireGuard - unbound (DNS caching) - ISC DHCP server It could act as the primary mail server too. It is, in fact, massive overkill for what I demand of it. Behind it is my house server, which happens to be the primary mail server, but more importantly in this scenario, runs another copy of the ISC DHCP server and BIND. DHCP failover is extremely simple in this combination; also, if the router is dead, we don't have Internet anyway. As it turns out, Verizon FIOS has been less reliable than this hardware. DHCP hands out addresses to devices it knows (registered MAC addresses) and those it doesn't (different IP subnet). That includes config hints on what DNS servers to use: the router and the house server. Unbound on the router is a general cache, and has entries to forward the ".internal" zone to BIND on the house server. If I want something to be accessible from the public world, it has a public DNS record: A, or AAAA or CNAME or MX, as appropriate. If I want it internally, it only appears in the .internal zone. If I didn't need to maintain my BIND skills for other reasons, I would probably use Unbound with Knot on both boxes. If I were optimizing for someone inexperienced to "fix the Internet!" while I wasn't around, I would probably get a really old small desktop with at least two NICs, set it up with basic routing and DNS resolving capabilities, test it, then turn it off. "Fix the Internet" would be a matter of unplugging the router and turning on the Emergency Backup Router. -dsr-
- References:
- [Discuss] Using public DNS for intranet hosts?
- From: dbarrett at blazemonger.com (Daniel Barrett)
- [Discuss] Using public DNS for intranet hosts?
- Prev by Date: [Discuss] Using public DNS for intranet hosts?
- Previous by thread: [Discuss] Using public DNS for intranet hosts?
- Index(es):
