CloudComputeGURU: cloud storage

Breaking

Showing posts with label cloud storage. Show all posts
Showing posts with label cloud storage. Show all posts
August 11, 2018

What Does DDNS (Dynamic DNS) Mean And How Does It Work?

DDNS stands for dynamic DNS, or more specifically dynamic Domain Name System. It's a service that maps internet domain names to IP addresses. It's a DDNS service that lets you access your home computer from anywhere in the world.


DDNS serves a similar purpose to the internet's Domain Name System (DNS) in that DDNS lets anyone hosting a web or FTP server advertise a public name to prospective users.

However, unlike DNS that only works with static IP addresses, DDNS is designed to also support dynamic (changing) IP addresses, such as those assigned by a DHCP server. That makes DDNS a good fit for home networks, which normally receive dynamic public IP addresses from their internet provider.

Note: DDNS is not the same as DDoS even though they share most of the same acronym letters.

How a DDNS Service Works
To use DDNS, just sign up with a dynamic DNS provider and install their software on the host computer. The host computer is whichever computer is used as the server, be it a file server, web server, etc.

What the software does is monitors the dynamic IP address for changes. When the address changes (which it eventually will, by definition), the software contacts the DDNS service to update your account with the new IP address.

This means so long as the DDNS software is always running and can detect a change in the IP address, the DDNS name you have associated with your account will continue to direct visitors to the host server no matter how many times the IP address changes.


The reason a DDNS service is unnecessary for networks that have static IP addresses is because the domain name doesn't need to know what the IP address is after it's initially told of it the first time. This is because static addresses don't change.

Why You Might Want a DDNS Service
A DDNS service is perfect if you host your own website from home, you have files you want to access no matter where you are, you like to remote into your computer when you're away, you like to manage your home network from afar, or any other similar reason.

Where to Get a Free or Paid DDNS Service
Several online providers offer free DDNS subscription services that support Windows, Mac, or Linux computers. A couple of my favorites include FreeDNS Afraid and NoIP.

However, something you should know about free DDNS service is that you can't just choose any URL and expect to have it forwarded to your server. For instance, you can't pick files.google.org as your file server address. Instead, after choosing a hostname, you're given a limited selection of domains to choose from.

For example, if you use NoIP as your DDNS service, you can pick a hostname that's your name or some random word or mixture of words, like my1website, but the free domain options are hopto.org, zapto.org, systes.net, and ddns.net. So, if you chose hopto.org, your DDNS URL would be my1website.hopto.org.

Other providers like Dyn offer paid options. Google Domains includes dynamic DNS support, too.
August 11, 2018

What Is "Reverse DNS" And Do I Need It?

Reverse DNS is IP address to domain name mapping - the opposite of forward (normal) DNS which maps domain names to IP addresses.

Reverse DNS is separate from forward DNS.
Forward DNS for "abc.com" pointing to IP address "1.2.3.4", does not necessarily mean that reverse DNS for IP "1.2.3.4" also points to "abc.com".
This comes from two separate sets of data.


A special PTR-record type is used to store reverse DNS entries. The name of the PTR-record is the IP address with the segments reversed + ".in-addr.arpa".
For example the reverse DNS entry for IP 1.2.3.4 would be stored as a PTR-record for "4.3.2.1.in-addr.arpa".

Reverse DNS is also different from forward DNS in who points the zone (domain name) to your DNS server.
With forward DNS, you point the zone to your DNS server by registering that domain name with a registrar.
With reverse DNS, your Internet connection provider (ISP) must point (or "sub-delegate") the zone ("....in-addr.arpa") to your DNS server.
Without this sub-delegation from your ISP, your reverse zone will not work.

Reverse DNS is mostly used by humans for such things as tracking where a web-site visitor came from, or where an e-mail message originated etc.
It is typically not as critical in as forward DNS - visitors will still reach your web-site just fine without any reverse DNS for your web-server IP or the visitor's IP.

However reverse DNS is important for one particular application.
Many e-mail servers on the Internet are configured to reject incoming e-mails from any IP address which does not have reverse DNS.
So if you run your own e-mail server, reverse DNS must exist for the IP address that outgoing e-mail is sent from.
It does not matter what the reverse DNS record for your IP address points to as long as it is there. If you host multiple domains on one e-mail server, just setup reverse DNS to point to whichever domain name you consider primary.
(e-mail servers checking for reverse DNS do recognize that it is normal to host many domains on a single IP address and it would be impossible to list all those domains in reverse DNS for the IP).

Special note about AOL:
It appears that AOL has recently restricted this even further:
They also require that reverse DNS points to a "fully qualified domain name" (we assume they mean a name with 3 or more segments, such as "mail.jhsoft.com"), and that this name does not contain the segments "in-addr.arpa" and is not just an IP address.
If you want to be able to send e-mail to AOL users, the reverse DNS record for your e-mail server IP address must adhere to this as well.
August 11, 2018

What is Round-Robin DNS? Everything You Need To Know

Round Robin DNS is a technique of load distribution, load balancing, or fault-tolerance provisioning multiple, redundant Internet Protocol service hosts, e.g., Web server, FTP servers, by managing the Domain Name System's (DNS) responses to address requests from client computers according to an appropriate statistical model.


In its simplest implementation, Round-robin DNS works by responding to DNS requests not only with a single potential IP address, but with one out of a list of potential IP addresses corresponding to several servers that host identical services. The order in which IP addresses from the list are returned is the basis for the term round robin. With each DNS response, the IP address sequence in the list is permuted. Usually, basic IP clients attempt connections with the first address returned from a DNS query, so that on different connection attempts, clients would receive service from different providers, thus distributing the overall load among servers.

There is no standard procedure for deciding which address will be used by the requesting application, a few resolvers attempt to re-order the list to give priority to numerically "closer" networks. Some desktop clients do try alternate addresses after a connection timeout of 30–45 seconds.

Round robin DNS is often used to load balance requests between a number of Web servers. For example, a company has one domain name and three identical copies of the same web site residing on three servers with three different IP addresses. When one user accesses the home page it will be sent to the first IP address. The second user who accesses the home page will be sent to the next IP address, and the third user will be sent to the third IP address. In each case, once the IP address is given out, it goes to the end of the list. The fourth user, therefore, will be sent to the first IP address, and so forth.

A round-robin DNS name is, on rare occasions, referred to as a "rotor" due to the rotation between alternative A records.

A load balancing technique in which balance power is placed in the DNS server instead of a strictly dedicated machine as other loadtechniques do.

Round robin works on a rotating basis in that one server IP addressis handed out, then moves to the back of the list; the next server IP address is handed out, and then it moves to the end of the list; and so on, depending on the number of servers being used. This works in a looping fashion.

Round robin DNS is usually used for balancing the load of geographically distributed Web servers. For example, a company has one domain name and three identical home pages residing on three servers with three different IP addresses. When one user accesses the home page it will be sent to the first IP address. The second user who accesses the home page will be sent to the next IP address, and the third user will be sent to the third IP address. In each case, once the IP address is given out, it goes to the end of the list. The fourth user, therefore, will be sent to the first IP address, and so forth.
August 11, 2018

DNS Management: Record Types and When To Use Them

In this article, we’re discussing a few of the more commonly used record types and when you might use them.


A Records
A Records are the most basic type of DNS record and are used to point a domain or subdomain to an IP address. Assigning a value to an A record is as simple as providing your DNS management panel with an IP address to where the domain or subdomain should point and a TTL.

A Record listing in the GoDaddy DNS Management Panel.
A Record listing in the GoDaddy DNS Management Panel.

The screenshot above is a sample of A Record listings of different types. You can see that the wildcard ( * ), @ symbol, and named host name entries were used. Here, the primary naked domain record (@) and blog subdomain point at the same IP address, but are separate records and can be changed individually at any time. A Records are only able to take an IP address as their value and you can point the same domain/subdomain to multiple IP addresses by adding another A Record with the same name but with a different IP address for the value.

You’ll want to use an A Record for your DNS entry if you have an IP address that the domain/subdomain should point to or if you want to establish a domain/subdomain to be used as the place to point a CNAME. You can find out more about why you might want to do this in the CNAME portion of this article.

CNAME
CNAME records are another commonly used type of DNS entry and are used to point a domain or subdomain to another hostname.

CNAME record listing in the GoDaddy DNS Management Panel.
CNAME record listing in the GoDaddy DNS Management Panel.

In the screenshot above, you can see immediately that one of the important differences from A Records is that the value portion of the record is required to be an existing subdomain/domain. You can see that the “journal” hostname points to my blog.iamrobertv.com A Record, which points to 198.101.164.57. What this means is that, if the value of the blog’s subdomain is ever changed, the journal subdomain’s value will also be changed.

As a host, we can use CNAMEs for customers as a means of being able to change the IP address of a server or cluster of servers transparently and without users having to make their own DNS adjustments. You can see an example of this in the store hostname that points to a cluster of servers of servers that sit behind the thor.openhostingservice.com subdomain. Finally, you can see the use of the @ symbol to indicate that the www hostname should point to the naked domain and use its value, which when you see the A Record sample image above, points to 198.101.164.57. This also means that, if the value of the naked/primary domain changes, the record of www will end up being affected accordingly.

MX Record
Mail Exchanger (MX) records are used to help route email according to the domain owners preference. The MX record itself specifies which server(s) to attempt to use to deliver mail to when this type of request is made to the domain. They differ from A Records and CNAMEs in the way that they also require a “priority” value as a part of their entry. The priority number is used to indicate which of the servers listed as MX records it should attempt to use first.

mx_record

In the screenshot above, you can see that I am using two MX records that have separate priority values and point to different subdomains. These subdomains are pointed at two different email servers that are designated to handle email. The MX record with the lower priority number (“0” in this case) is the first to be tried for email delivery. If this server is unable to handle the mail request, the next lowest priority number is used, which in this case would be 10.

Some email providers have only one MX record and some have well over two. The number of MX entries you will need to create depends largely on the mail provider and how they expect the load on these email servers to be handled.

Try the BEST WordPress hosting free for 15 days. Use code PRESS50OFFFOR2 at checkout and get 50% off your first 2 months.

You will notice the host name here is designated as the naked/primary form ( @ ). If you wanted to receive mail on a subdomain, you would adjust the hostname accordingly and ensure your email provider is setup to handle email from the subdomain.

TXT Record
A TXT record is used to store any text-based information that can be grabbed when necessary. We most commonly see TXT records used to hold SPF data and verify domain ownership.

TXT Record listing in the GoDaddy DNS Management Panel.
TXT Record listing in the GoDaddy DNS Management Panel.

The screenshot above gives an example of how a TXT value would be formed for both an SPF entry or an ownership verification for the naked/primary host/name using the @ symbol. If you need to verify or provide an SPF record for a specific subdomain, then you will need to use the appropriate hostname in place of the @ symbol. The rule of thumb for TXT records is that they require an attribute name, followed by an equals sign, followed by a value for the attribute. You can use this to relay any sort of information you’d like using a DNS record, so long as you have a purpose for it and the record is properly formatted.

We won’t go into the details of properly formed SPF records and what their different pieces mean, but these will commonly be supplied to you by the mail provider you are working with. In the same way, places that require domain verification through use of a TXT record will also provide you with a properly formatted TXT record value to use.

Final Thoughts
Managing your own DNS can be a tricky endeavor, especially if you haven’t ever considered what this means or ever even seen a DNS record. Ideally, this series of articles will help you understand the general how a website’s DNS works for a domain from the time it is typed into the browser to the time your name servers handle the request. Although it can be rather easy to understand the record types themselves, knowing about nameservers, registrars, and how a specific set of DNS records gets chosen and used is a little more difficult to navigate, but is just as essential to know.
August 11, 2018

How To Change Your DNS To See If Cloudflare Can Speed Up Your Internet

A couple days ago, Cloudflare launched its own DNS service at 1.1.1.1, promising that consumers would enjoy greater privacy and potentially faster internet if they switched over from their ISP’s default. Now, those speed differences might not be significant or noticeable enough to the point of making the switch full-time. (We’re talking milliseconds here.) But it doesn’t take many steps to test out a new DNS, so it’s probably worth a quick try if you’re curious or sold on Cloudflare’s privacy measures.


The Domain Name System (DNS) is what converts domain names into IP addresses. And the best way to change your DNS is by adjusting your router’s settings. This automatically makes any devices joining your Wi-Fi network use the new DNS without having to go in and configure each device individually. It’s just a much easier approach.

WHAT ARE SOME POPULAR DNS OPTIONS BESIDES MY ISP’S DEFAULT?
Google Public DNS:

Primary: 8.8.8.8
Secondary: 8.8.4.4

OpenDNS

Primary: 208.67.222.222
Secondary: 208.67.220.220

Cloudflare

Primary: 1.1.1.1
Secondary: 1.0.0.1

CHANGE DNS FOR ALL DEVICES THAT CONNECT TO YOUR ROUTER (BEST OPTION)
Linksys

Sign in to your Linksys router’s admin page, which is almost certainly 192.168.1.1. Click “Setup” from the top menu. From there, choose “Basic Setup,” and enter the new DNS info into the Status DNS 1 and 2 fields. Save settings, and you’re done. You shouldn’t need to reset your router for the change to take effect.

Netgear

When connected to your Wi-Fi, visit http://www.routerlogin.com or http://www.routerlogin.net in a web browser. Log in with your administrator credentials. Click “Internet” and then select “Use these DNS Servers” and enter the primary and secondary addresses. Then click “Apply.” Done.

D-Link

Open your router administration page at wither 192.168.1.1 or 192.168.0.1. Log in with your password, and then choose “Manual Internet Connection Setup.” Fill in the DNS server fields with the primary and secondary DNS addresses.

Google Wifi

Open the Google Wifi app, go to the settings tab, then pick “networking & general.” Tap on advanced network, and then DNS. Choose “custom,” and then enter your new primary and secondary DNS addresses.

Eero

From the Network Settings page, to go Advanced, then choose DNS. Tap “Custom DNS,” and enter your primary and secondary DNS.

CHANGE DNS FOR INDIVIDUAL DEVICES
Windows

Open the Control Panel. Click on Network and Internet, and then Network and Sharing Center. Choose “Change Adapter Settings” from the list on the left.

Next, right click on whatever Wi-Fi network you’re currently on, and choose Properties. Select Internet Protocol Version 4 (TCP/IPv4), and then click Properties.

Click “Use The Following DNS Server Addresses,” and replace whatever’s there with your new DNS. In the case of Cloudflare, you’d enter 1.1.1.1 and 1.0.0.1. Click OK, followed by Close, and you’re done.

Android

Android requires a static IP address to use custom DNS addresses, which takes additional setup steps. The router approach is recommended here.

If you’ve already done that, go to settings, then Wi-Fi. Long-press on your current Wi-Fi network and choose “Modify Network.” You might need to go to an advanced section depending on your Android device’s software. Add your new primary and secondary DNS addresses to the DNS 1 and DNS 2 fields.

iOS

Go to settings. Pick Wi-Fi, then tap the blue “i” next to your preferred network. Tap “Configure DNS” and make sure it’s set to manual, not automatic. Then delete any entries under DNS services and choose “Add Server” to enter your new DNS resolver. Using Google Public DNS as an example, you would add two entries: 8.8.8.8 and 8.8.4.4. Save your changes, and you’re done.

macOS

Open System Preferences. Instead of clicking through numerous menus, the fastest way to get where you want to be is just by searching for “DNS servers” at the top right. That’ll take you to the right screen, where you can click the + symbol to add whichever DNS you want to try.
August 11, 2018

A Comparison Of Dns Server Types Choose The Right Dns Configuration

DNS, or the Domain Name System, is an intrinsic part of how systems connect with each other to communicate on the internet. Without DNS, experts, and the people who use them, would be demanded to connect using only quantitative addresses known as IP addresses.


Besides the obvious difficulty of having to remember a huge number of complex numbers for easy tasks, communicating through IP addresses also ventures some more difficulties. Moving your website to a dissimilar entertaining provider, or moving your servers to dissimilar venues would demand you to inform every client of the brand-new area.

DNS servers, the experts that together form the system that allow us to use names instead of addresses, can server many non-identical functions, each of which can contribute to your ability to accessing servers by name.

In a preceding lead we discussed some of the basic word and ideas of the domain name system. We will assume some familiarity with the ideas covered in that article. In this lead, we will talk about some of the disparate types of DNS server setups and what the merits, use cases, and properties are of each.

The Path of a DNS Query
When a client software wants to accesses a server by its domain name, it must find out how to translate the domain name into an effective routable addresses that it can use to communicate. It needs to know this information in order to get or send information to the server.

Some applications, including most web browsers, maintain an inner cache of new queries. This is the first place the application will check, if it has this aptitude, in order to find the IP addresses of the domain in ask. If it does not find the reply to its ask here, it then asks the system resolver to find out what the addresses of the domain name is.

A resolver in general is any element that acts as a client-side contestant in a dns query. The system resolver is the resolving library that your directing system uses to seek out the reply for DNS queries. In general, system resolvers are usually what we consider receipt resolvers because they are not able of much quality beyond searching a few nonmoving records on the system (like the /etc/hosts register) and forwarding requests to another resolver.

So generally, a query goes from the client application to the system resolver, where it is then passed to a dns server that it has the addresses for. This DNS server is labelled a recursive DNS server. a recursive server is a dns server that is configured to query other DNS servers until it finds the reply to the request. It will either return the reply or an error communication to the client (the system resolver in this case, which will, in turn, pass it to the client application).

Recursive servers generally maintain a cache as well. It will check this cache first to see if it already has the reply to the query. If it does not, it will see if it has the addresses to any of the servers that command the top stage domain elements. So if the ask is for www.instance.com and it cannot find that host addresses in its cache, it will see if it has the addresses of the name servers for instance.com and if necessary, com. It will then send a query to the name server of most exact domain element it can find in order to query for more information.

If it does not find the addresses to any of these domain elements, it has to begin from the very top of the hierarchy by asking the set name servers. The set servers know the addresses of all of the TLD (top stage domain) name servers which command zones for .com, .clear, .org, etc. It will question the set servers if it knows the addresses of to www.instance.com. The set server will refer the recursive server to the name servers for the .com TLD.

The recursive server then follows the trail of forwardings to each ordered name server that has been delegated responsibility for the domain elements, until it can zero in on the accurate name server that has the full reply. It puts this reply into its cache for later queries and then returns it to the client.

As you can see from this instance, there are many dissimilar categories of servers, and they each play a dissimilar role. Let's go over the accurates of the dissimilar types of DNS servers.

Functional Differences
Some of the disagreements between DNS servers are purely structural. Most servers that are involved with implementing DNS are differentiated for definite functions. The symbol of DNS server you choose will largely be on your needs and what symbol of difficulty you are wishing to unravel.

Authoritative-Only DNS Servers
an authoritative-only DNS server is a server that only concerns itself with replying the queries for the zones that it is accountable for. Since it does not support resolve queries for outside zones, it is generally very swift and can handle many requests efficiently.

Authoritative-only servers have the following properties:

Very swift at answering to queries for zones it regulates. an authoritative-only server will have all of the information about the domain it is accountable for, or forwarding information for zones within the domain that have been delegated out to other name servers.
Will not reply to recursive queries. The very definition of an authoritative-only server is one that does not handle recursive requests. This makes it a server only and never a client in the DNS system. Any question approaching an authoritative-only server will generally be approaching from a resolver that has collected a forwarding to it, conveying that the authoritative-only server will either have the full reply, or will be able to pass a brand-new forwarding to the name server that it has delegated responsibility to.
Does not cache query results. Since an authoritative-only server never queries other servers for information to resolve a question, it never has the opportunity to cache results. All of the information it knows is already in its system.
Caching DNS Server
a caching DNS server is a server that handles recursive requests from cases. Almost every DNS server that the directing system's receipt resolver will contact will be a caching DNS server.

Caching servers have the merit of replying recursive requests from cases. While authoritative-only servers may be perfect for serving precise zone information, caching DNS servers are more broadly helpful from a client's orientation. They make the DNS system of the experience accessible to rather stupid client interfaces.

To evade having to take the performance knocked of issuing aggregate aspect ask to other DNS servers every moment it receives a recursive ask, the server caches its results. This allows it to have accesses to a beamy base of DNS information (the whole world's publicly accessible DNS) while handling new requests very quickly.

a caching DNS server has the following properties:

accesses to the whole range of public DNS data. All zone data served by publicly accessible DNS servers hooked into the international delegation tree can be approached by a caching DNS server. It knows about the set DNS servers and can intelligently follow forwardings as it receives data.
Ability to spoon-feed data to stupid cases. Almost every modern operating system offloads DNS resolution to dedicated recursive servers through the use of receipt resolvers. These resolving libraries simply issue a recursive request and expect to be handed back a complete answer. A caching DNS server has the exact capabilities to serve these clients. By accepting a recursive query, these servers promise to either return with an answer or a DNS error message.
Maintains a cache of recently questioned data. By caching the results as it collects them from other DNS servers for its client requests, a caching DNS server builds a cache for new DNS data. being on how many cases use the server, how huge the cache is, and how long the TTL data is on the DNS records themselves, this can drastically speed up DNS resolution in most cases.
Forwarding DNS Server
an alternative take on creating a cache for client appliances is through the use of a forwarding DNS server. This come adds an extra link in the series of DNS resolution by implementing a forwarding server that simply passes all requests to another DNS server with recursive aptitudes (such as a caching DNS server).

The merit of this system is that it can give you the merit of a locally accessible cache while not having to do the recursive work (which can result in more network traffic and can take up considerable resources on high traffic servers). This can also govern to some captivating trait in splitting your independent and public traffic by forwarding to disparate servers.

a forwarding DNS server has the following properties:

The ability to handle recursive requests without performing recursion itself. The most important property of a forwarding DNS server is that it passes requests on to another agent for resolution. The forwarding server can have minimal resources and still give fantastic ideal by supplementing its cache.
give a local cache at a closer network venue. Particularly if you do not feel up to building, maintaining, and obtaining a full-fledged recursive DNS success, a forwarding server can use public recursive DNS servers. It can leverage these servers while moving the capital caching venue very close to the client gagdets. This can decrease respond times.
Increases trait in being local domain space. By passing requests to disparate servers conditionally, a forwarding server can ensure that inner requests are served by independent servers while outer requests use public DNS.
Combination Solutions
While the above successes are built with very precise purposes in mind, it is often desirable to set up your DNS server to combine the merits of each.

a dns server may be configured to act as a recursive, caching server for a specify number of local cases, while responding only aspect, influential requests from other cases. This is a communal configuration because it allows you to respond international requests for your domain, while also allowing your local cases to utilize the server for recursive resolution.

While definite DNS program is specially designed to fulfill one accurate role, applications like Bind are incredibly flexible and can be used as crossbred successes. While in some cases striving to give too many services in an individual server can guide to performance degradation, in many cases, especially in the case of little structure, it makes the most sense to maintain an individual, all-in-one success.

Relational Differences
While the most obvious disagreements between DNS server configurations are probably structural, the relative disagreements are also extremely all-important.

Primary and Slave Servers
Given the value of DNS in making services and whole networks accessible, most DNS servers that are influential for a zone will have built-in redundancy. There are different terms for the relations between these servers, but generally, a server can either be a leader or a slave in its configuration.

Both leader and slave servers are authoritative for the zones they handle. The leader does not have any more power over the zones than the slave. The only differentiating factor between a leader and a slave server is where they read their zone files from.

A leader server reads its zone files from files on the system's disk. These are usually where the zone administrator adds, edits, or transfers the original zone files.

The slave server receives the zones that it is authoritative for through a zone transfer from one of the leader servers for the zone. Once it has these zones, it places them in a cache. If it has to restart, it first checks its cache to see if the zones inside are up-to-date. If not, it requests the updated information from the leader server.

Servers are not relegated to only be a leader or a slave for all of the zones they handle. Master or slave status is assigned on a zone-by-zone basis, so a server can be a leader for some zones and a slave for others.

DNS zones usually have at least two name servers. Any zone accountable for an internet routable zone must have at least two name servers. Often times, many more name servers are maintained in order to spread the load and increase redundancy.

Public vs Private Servers
Often, organizations use DNS both externally and internally. However the information that should be made accessible in both of these spheres is often drastically non-identical.

an organization might maintain an externally accessible influential-only DNS server to handle public DNS queries for the domains and zones that it handles. For its inner users, the organization might use an apart DNS server that contains the influential information that the public DNS provides, as well as extra information about inner hosts and services. It might also give extra features, such as recursion and caching for its inner cases.

While we mentioned the ability to have a solo server handle all of these tasks in the "combination" server above, there are certain benefits to splitting the workload. In information, maintaining completely apart servers (inner vs outer) that have no knowledge of each other is often desirable. It is especially all-important, from a security standpoint, that the public server has no records of the independent equivalent. This means not listing your independent name servers with NS records in the public zone records.

There are some additional considerations to keep in mind. While it might be easier to have your public and private servers share zone data that they have in common in a traditional leader-slave relationship, this can leak information about your private infrastructure into the wild.

Beyond just keeping your private servers out of the zone files themselves (essentially a publicly searchable entity), it is usually a good idea to also remove any reference to the private server in the public server's configuration files. This means removing transfer, notify, and leaders configuration details so that a compromise of the public server does not mean that your internal name servers are suddenly exposed.

This means maintaining apart zone records for each, which can be more work. However, this may be necessary for direct separation and security.
August 11, 2018

Understanding The Difference Between A Primary And Secondary DNS Server

DNS stands for domain name system, the largest database in the world, containing all registration information pertaining to every domain name in existence. A DNS server, also commonly referred to as a name server, is simply a web server that is equipped with software that allows it to connect and or interact with this database on a regular basis. Data contained within the domain name system includes but is not limited to information related to the web host, the domain registrant, and the active name servers for the domain. Every domain name has at least two name servers, provided by a hosting provider.


Understanding Name Servers

There are literally tens of thousands of DNS servers located throughout the world that each contain a portion of the domain name system database. To maintain redundancy and security of this database there are also 13 root DNS servers that contain the entirety of the database on each server. There are two main types of DNS servers – primary DNS servers and secondary DNS servers. It should be noted that any web server can be used as a DNS server, and any DNS server can be designated as a primary or secondary server. The server administrator has the choice of designating a server as a primary or secondary server, and it is even possible for a single server to be used as a primary server in a zone, while simultaneously being used as a secondary server in another zone.

What are Primary DNS Servers?

A primary DNS server is responsible for reading data related to the domain zone. The primary server is also responsible for communicating with the secondary server. Data pertaining to the domain zone is specifically designated by server administrators, who instruct the server on how to communicate and interact with other web servers. The process of a primary web server communicating with the secondary server is known as a zone transfer, as zone data is being sent from a DNS server to another. Each domain name is assigned to DNS servers for redundancy, and to simplify the process of server administration. If a primary server already contains the zone data for a domain, this data does not need to be replicated because the primary and secondary server continuously share zone data. In basic terms, when a request is issued to a server it travels through the primary DNS server, which then allocates functions to a secondary server.

What are Secondary DNS Servers?

A secondary DNS server, also commonly referred to as a slave server, is responsible for obtaining zone data from the primary DNS server immediately after being set up. Each time a secondary DNS server functions it receives information from the primary DNS server. However, it should be noted that a secondary DNS server does not necessarily need to obtain information from a primary DNS server, as other secondary servers can be set up as master servers. Secondary servers are nearly as important as primary DNS servers because they offer security through redundancy. Secondary servers also mitigate the total resource load put on the primary DNS server.

So, What Exactly is DNS?

In the simplest definition, DNS is the term used to describe a system that assigns user-friendly names to unique IP addresses. It translates unfathomable amounts of data into words and phrases in order to provide clear and accurate search results.
August 11, 2018

What Is Open DNS? Everything You Need To Know


Definition - What does OpenDNS mean?
OpenDNS is the name of a Domain Name System (DNS) service as well as of the company that provides that service. The OpenDNS service extends the DNS by incorporating features such as content filtering and phishing protection. It is also touted as faster, more reliable and having zero downtime because of its global network of DNS servers that ensures that, if one or two servers are down, the others can still carry the slack.

Techopedia explains OpenDNS
OpenDNS, the company, provides a DNS service a step above those being provided by Internet service providers (ISPs) around the globe. DNS is an integral part of the World Wide Web that allows both humans and computers to understand each other when it comes to Web addresses; humans can identify words easily (domain names), whereas computers rely on numerical values (the IP address of a website). DNS is a directory service, and DNS servers are essentially lookup tables containing the associations between domain names and their respective IP addresses. The DNS server essentially points the user's request toward the correct address of the computer/server that hosts the website being requested.

OpenDNS extends the DNS service by improving the efficiency of the system by adding more servers across the globe that can detect the nearest server to the user and use that to serve the user's requests. This improves the efficiency since regular ISP-driven DNS servers are few and usually far away from most users. It also adds another layer of security through PhishTank, its anti-fishing service that takes the guesswork out of distinguishing phishing websites from the originals, and now also offers a cloud-delivered network security product called Umbrella. Added parental controls also allow filtering of websites and website contents. OpenDNS is free for its basic services, but advanced services targeted for businesses and larger institutions have subscription fees.
August 11, 2018

What Is DNS (Domain Names Servers) And How Does It Work?

The Domain Name System (DNS) is one of the foundations of the internet, yet most people outside of networking probably don’t realize they use it every day to do their jobs, check their email or waste time on their smartphones.


At its most basic, DNS is a directory of names that match with numbers. The numbers, in this case are IP addresses, which computers use to communicate with each other. Most descriptions of DNS use the analogy of a phone book, which is fine for people over the age of 30 who know what a phone book is.

If you’re under 30, think of DNS like your smartphone’s contact list, which matches people’s names with their phone numbers and email addresses. Then multiply that contact list by everyone else on the planet.

When the internet was very, very small, it was easier for people to correspond specific IP addresses with specific computers, but that didn’t last for long as more devices and people joined the growing network. In addition to creating a directory for all of these devices, words were used to let people connect to different sites; for most people, remembering words is easier than remembering specific sets of numbers. It is still possible to type in a specific IP address into a browser to reach a website.

How DNS servers work
The DNS directory that matches name to numbers isn’t located all in one place in some dark corner of the internet. Like the internet itself, the directory is distributed around the world, stored on domain name servers that all communicate with each other on a very regular basis to provide updates and redundancies. With more than 332 million domain names listed at the end of 2017, a single directory would be very large indeed.

Each named site can correspond to more than one IP address. In fact, some sites have hundreds or more IP addresses that correspond with a single domain name. For example, the server your computer reaches for www.google.com is likely completely different from the server that someone in another country would reach by typing the same site name into their browser.

Another reason for the distributed nature of the directory is the amount of time it would take for you to get a response when you were looking for a site if there was only one location for the directory, shared among the millions, probably billions, of people also looking for information at the same time. That’s one long line to use the phone book.

Instead, DNS information is shared among many servers, but is also cached locally on client computers. Chances are that you use google.com several times a day. Instead of your computer querying the DNS name server for the IP address of google.com every time, that information is saved on your computer so it doesn’t have to access a DNS server to resolve the name with its IP address. Additional caching can occur on the routers used to connect clients to the internet, as well as on the servers of the user’s Internet Service Provider (ISP). With so much caching going on, the number of queries that actually make it to DNS name servers is a lot lower than it would seem.

How DNS adds efficiency
DNS is organized in a hierarchy that helps keep things running quickly and smoothly. To illustrate, let’s pretend that you wanted to visit networkworld.com.

The initial request for the IP address is made to a recursive resolver, a server that is usually operated by an ISP or other third-party provider. The recursive resolver knows which other DNS servers it needs to ask to resolve the name of a site (networkworld.com) with its IP address. This search leads to a root server, which knows all the information about top-level domains, such as .com, .net, .org and all of those country domains like .cn (China) and .uk (United Kingdom). Root servers are located all around the world, so the system usually directs you to the closest one geographically.

Once the request reaches the correct root server, it goes to a top-level domain (TLD) name server, which stores the information for the second-level domain, the words used before you get to the .com, .org, .net (for example, that information for networkworld.com is “networkworld”). The request then goes to the Domain Name Server, which holds the information about the site and its IP address. Once the IP address is discovered, it is sent back to the client, which can now use it to visit the website. All of this takes mere milliseconds.

Because DNS has been working for the past 30+ years, most people take it for granted. Security also wasn’t considered when building the system, so hackers have taken full advantage of this, creating a variety of attacks.

DNS reflection attacks
DNS reflection attacks can swamp victims with high-volume messages from DNS resolver servers. Attackers request large DNS files from all the open DNS resolvers they can find and do so using the spoofed IP address of the victim. When the resolvers respond, the victim receives a flood of unrequested DNS data that overwhelms their machines.

DNS cache poisoning
DNS cache poisoning can divert users to malicious Web sites. Attackers manage to insert false address records into the DNS so when a potential victim requests an address resolution for one of the poisoned sites, the DNS responds with the IP address for a different site, one controlled by the attacker. Once on these phony sites, victims may be tricked into giving up passwords or suffer malware downloads.

DNS resource exhaustion
DNS resource exhaustion attacks can clog the DNS infrastructure of ISPs, blocking the ISP’s customers from reaching sites on the internet. This can be done by attackers registering a domain name and using the victim’s name server as the domain’s authoritative server. So if a recursive resolver can’t supply the IP address associated with the site name, it will ask the name server of the victim. Attackers generate large numbers of requests for their domain and toss in non-existent subdomains to boot, which leads to a torrent of resolution requests being fired at the victim’s name server, overwhelming it.

What is DNSSec?
DNS Security Extensions is an effort to make the communication among the various levels of servers involved in DNS lookups more secure. It was devised by the Internet Corporation for Assigned Names and Numbers (ICANN), the organization in charge of the DNS system.

ICANN became aware of weaknesses in the communication between the DNS top-level, second-level and third-level directory servers that could allow attackers to hijack lookups. That would allow the attackers to respond to requests for lookups to legitimate sites with the IP address for malicious sites. These sites could upload malware to users or carry out phishing and pharming attacks.

DNSSEC would address this by having each level of DNS server digitally sign its requests, which insures that the requests sent in by end users aren’t commandeered by attackers. This creates a chain of trust so that at each step in the lookup, the integrity of the request is validated.

In addition, DNSSec can determine if domain names exist, and if one doesn’t, it won’t let that fraudulent domain be delivered to innocent requesters seeking to have a domain name resolved.

As more domain names are created, and more devices continue to join the network via internet of things devices and other “smart” systems, and as more sites migrate to IPv6, maintaining a healthy DNS ecosystem will be required. The growth of big data and analytics also brings a greater need for DNS management.