[Discuss] Using public DNS for intranet hosts?
Dan Ritter
dsr at randomstring.org
Sat Aug 29 14:30:42 EDT 2026
Daniel Barrett wrote:
> Rich Pieri <richard.pieri at gmail.com> wrote:
> >On Fri, 28 Aug 2026 15:42:05 -0400 Daniel Barrett <dbarrett at blazemonger.com> wrote:
>
> Thanks. I'm curious, is it a "bad idea" just because it's an ugly
> hack, or is there another reason? (FWIW, I ran a test, and my
> registrar's DNS software accepts an A record of this sort without any
> complaint, and tech support told me it doesn't seem to violate any of
> their policies.)
It's the sort of thing which gets an organization with more than
one sysadmin in trouble. You can do this, if you really want to.
> >The correct solution is to run a little caching nameserver inside your
> >private network and put your private records here.
>
> I totally agree, and that would be a great suggestion if I were not
> the only person with sysadmin skills in my household, but I am. I
> can't have non-spouse-compatible solutions in place, like a headless
> Raspberry Pi in the basement, that nobody else can maintain if I die
> or am unavailable. That's why I mentioned my spouse in my original
> post.
Are you sure you're not falling prey to https://xkcd.com/2501/ ?
My kids (college-age plus) vaguely know what DNS is, but I don't
think they'd get around to diagnosing a problem as "the DNS
server isn't responding".
My spouse, on the other hand, has led large and small ISP
customer support teams, and ... might think about it, but
probably not.
> Any alternative suggestions/feedback? Thank you very much.
Wall of descriptive text incoming, you have been warned.
The house router is a headless, fanless microPC -- pretty similar
to this one:
https://www.amazon.com/Sharevdi-Fanless-Firewall-Ethernet-Gigabit/dp/B0F7XMZC1D
It runs Debian stable, and beyond being a firewall/router, it runs:
- ntp
- a dynamic DNS client
- WireGuard
- unbound (DNS caching)
- ISC DHCP server
It could act as the primary mail server too. It is, in fact,
massive overkill for what I demand of it.
Behind it is my house server, which happens to be the primary
mail server, but more importantly in this scenario, runs another
copy of the ISC DHCP server and BIND.
DHCP failover is extremely simple in this combination; also, if
the router is dead, we don't have Internet anyway. As it turns
out, Verizon FIOS has been less reliable than this hardware.
DHCP hands out addresses to devices it knows (registered MAC
addresses) and those it doesn't (different IP subnet). That
includes config hints on what DNS servers to use: the router and
the house server.
Unbound on the router is a general cache, and has entries to
forward the ".internal" zone to BIND on the house server.
If I want something to be accessible from the public world, it
has a public DNS record: A, or AAAA or CNAME or MX, as
appropriate. If I want it internally, it only appears in the
.internal zone.
If I didn't need to maintain my BIND skills for other reasons, I
would probably use Unbound with Knot on both boxes.
If I were optimizing for someone inexperienced to "fix the
Internet!" while I wasn't around, I would probably get a really
old small desktop with at least two NICs, set it up with basic
routing and DNS resolving capabilities, test it, then turn it
off. "Fix the Internet" would be a matter of unplugging the
router and turning on the Emergency Backup Router.
-dsr-
More information about the Discuss
mailing list