CloudComputeGURU: dns

Breaking

Showing posts with label dns. Show all posts
Showing posts with label dns. Show all posts
August 11, 2018

What Does DDNS (Dynamic DNS) Mean And How Does It Work?

DDNS stands for dynamic DNS, or more specifically dynamic Domain Name System. It's a service that maps internet domain names to IP addresses. It's a DDNS service that lets you access your home computer from anywhere in the world.


DDNS serves a similar purpose to the internet's Domain Name System (DNS) in that DDNS lets anyone hosting a web or FTP server advertise a public name to prospective users.

However, unlike DNS that only works with static IP addresses, DDNS is designed to also support dynamic (changing) IP addresses, such as those assigned by a DHCP server. That makes DDNS a good fit for home networks, which normally receive dynamic public IP addresses from their internet provider.

Note: DDNS is not the same as DDoS even though they share most of the same acronym letters.

How a DDNS Service Works
To use DDNS, just sign up with a dynamic DNS provider and install their software on the host computer. The host computer is whichever computer is used as the server, be it a file server, web server, etc.

What the software does is monitors the dynamic IP address for changes. When the address changes (which it eventually will, by definition), the software contacts the DDNS service to update your account with the new IP address.

This means so long as the DDNS software is always running and can detect a change in the IP address, the DDNS name you have associated with your account will continue to direct visitors to the host server no matter how many times the IP address changes.


The reason a DDNS service is unnecessary for networks that have static IP addresses is because the domain name doesn't need to know what the IP address is after it's initially told of it the first time. This is because static addresses don't change.

Why You Might Want a DDNS Service
A DDNS service is perfect if you host your own website from home, you have files you want to access no matter where you are, you like to remote into your computer when you're away, you like to manage your home network from afar, or any other similar reason.

Where to Get a Free or Paid DDNS Service
Several online providers offer free DDNS subscription services that support Windows, Mac, or Linux computers. A couple of my favorites include FreeDNS Afraid and NoIP.

However, something you should know about free DDNS service is that you can't just choose any URL and expect to have it forwarded to your server. For instance, you can't pick files.google.org as your file server address. Instead, after choosing a hostname, you're given a limited selection of domains to choose from.

For example, if you use NoIP as your DDNS service, you can pick a hostname that's your name or some random word or mixture of words, like my1website, but the free domain options are hopto.org, zapto.org, systes.net, and ddns.net. So, if you chose hopto.org, your DDNS URL would be my1website.hopto.org.

Other providers like Dyn offer paid options. Google Domains includes dynamic DNS support, too.
August 11, 2018

How To Change Your DNS To See If Cloudflare Can Speed Up Your Internet

A couple days ago, Cloudflare launched its own DNS service at 1.1.1.1, promising that consumers would enjoy greater privacy and potentially faster internet if they switched over from their ISP’s default. Now, those speed differences might not be significant or noticeable enough to the point of making the switch full-time. (We’re talking milliseconds here.) But it doesn’t take many steps to test out a new DNS, so it’s probably worth a quick try if you’re curious or sold on Cloudflare’s privacy measures.


The Domain Name System (DNS) is what converts domain names into IP addresses. And the best way to change your DNS is by adjusting your router’s settings. This automatically makes any devices joining your Wi-Fi network use the new DNS without having to go in and configure each device individually. It’s just a much easier approach.

WHAT ARE SOME POPULAR DNS OPTIONS BESIDES MY ISP’S DEFAULT?
Google Public DNS:

Primary: 8.8.8.8
Secondary: 8.8.4.4

OpenDNS

Primary: 208.67.222.222
Secondary: 208.67.220.220

Cloudflare

Primary: 1.1.1.1
Secondary: 1.0.0.1

CHANGE DNS FOR ALL DEVICES THAT CONNECT TO YOUR ROUTER (BEST OPTION)
Linksys

Sign in to your Linksys router’s admin page, which is almost certainly 192.168.1.1. Click “Setup” from the top menu. From there, choose “Basic Setup,” and enter the new DNS info into the Status DNS 1 and 2 fields. Save settings, and you’re done. You shouldn’t need to reset your router for the change to take effect.

Netgear

When connected to your Wi-Fi, visit http://www.routerlogin.com or http://www.routerlogin.net in a web browser. Log in with your administrator credentials. Click “Internet” and then select “Use these DNS Servers” and enter the primary and secondary addresses. Then click “Apply.” Done.

D-Link

Open your router administration page at wither 192.168.1.1 or 192.168.0.1. Log in with your password, and then choose “Manual Internet Connection Setup.” Fill in the DNS server fields with the primary and secondary DNS addresses.

Google Wifi

Open the Google Wifi app, go to the settings tab, then pick “networking & general.” Tap on advanced network, and then DNS. Choose “custom,” and then enter your new primary and secondary DNS addresses.

Eero

From the Network Settings page, to go Advanced, then choose DNS. Tap “Custom DNS,” and enter your primary and secondary DNS.

CHANGE DNS FOR INDIVIDUAL DEVICES
Windows

Open the Control Panel. Click on Network and Internet, and then Network and Sharing Center. Choose “Change Adapter Settings” from the list on the left.

Next, right click on whatever Wi-Fi network you’re currently on, and choose Properties. Select Internet Protocol Version 4 (TCP/IPv4), and then click Properties.

Click “Use The Following DNS Server Addresses,” and replace whatever’s there with your new DNS. In the case of Cloudflare, you’d enter 1.1.1.1 and 1.0.0.1. Click OK, followed by Close, and you’re done.

Android

Android requires a static IP address to use custom DNS addresses, which takes additional setup steps. The router approach is recommended here.

If you’ve already done that, go to settings, then Wi-Fi. Long-press on your current Wi-Fi network and choose “Modify Network.” You might need to go to an advanced section depending on your Android device’s software. Add your new primary and secondary DNS addresses to the DNS 1 and DNS 2 fields.

iOS

Go to settings. Pick Wi-Fi, then tap the blue “i” next to your preferred network. Tap “Configure DNS” and make sure it’s set to manual, not automatic. Then delete any entries under DNS services and choose “Add Server” to enter your new DNS resolver. Using Google Public DNS as an example, you would add two entries: 8.8.8.8 and 8.8.4.4. Save your changes, and you’re done.

macOS

Open System Preferences. Instead of clicking through numerous menus, the fastest way to get where you want to be is just by searching for “DNS servers” at the top right. That’ll take you to the right screen, where you can click the + symbol to add whichever DNS you want to try.
August 11, 2018

DNS Security Extensions (DNSSEC) What Is It and Why Is It Important?

DNS Security Extensions (DNSSEC) are a set of Internet Engineering Task Force (IETF) standards created to address vulnerabilities in the Domain Name System (DNS) and protect it from online threats. The purpose of DNSSEC is to increase the security of the Internet as a whole by addressing DNS security weaknesses. Essentially, DNSSEC adds authentication to DNS to make the system more secure. 


The Domain Name System manages Internet navigation by locating domain names and mapping them to IP addresses. DNS, as originally designed, has no means of determining whether domain name data comes from the authorized domain owner or has been forged. This security weakness leaves the system vulnerable to a number of attacks, such as DNS cache poisoning, for example.

In a DNS cache poisoning attack, an intruder replaces a valid IP address cached in a DNS table with a rogue address. Requests for the valid address are redirected accordingly, and malware -- such as a worm, spyware or browser hijacker -- may be downloaded to the user's computer from the rogue location. DNSSEC employs cryptographic keys and digital signatures to ensure that lookup data is correct and that connections are to legitimate servers.

The core elements of DNSSEC were specified in three IETF Requests for Comments published in March 2005: RFC 4033 - DNS Security Introduction and Requirements, RFC 4034 - Resource Records for the DNS Security Extensions, and RFC 4035 - Protocol Modifications for the DNS Security Extensions.

DNSSEC implementation is somewhat complex and is on a voluntary basis. As a result, adoption has been slow. In the United States, the federal government has mandated DNSSEC implementation for government networks. The National Institute of Standards and Technology (NIST) and the General Services Administration (GSA) have implemented the standards within the top level dot.gov domain. However, most individual agencies have yet to meet the mandate for second-level domains.

DNSSEC is offered as a managed service; DNSSEC appliances that automate the process are also available from some  vendors.
August 11, 2018

Introduction to Google Public DNS - How And Why You Should Use It

When people email us asking for help with their DNS configuration, we often point them at DNS lookup tools they can use to diagnose problems, but sometimes we're able to narrow down problems to local or ISP provided resolvers. At that point, we sometimes suggest switching to Google's Public DNS. Here's how you can do that and why you might want to consider it.


Google's Public DNS is fast
Google has their Public DNS service available on a global anycast network which provides all of the benefits of anycast for the queries made to them. For largely the same reasons that authoritative name servers on an anycast network provide a speed boost to your customers, anycast resolvers provide a speed boost to you by allowing your browser to make requests to the nearest name server available.

Additionally, Google has taken many steps to reduce latency in DNS queries, including some interesting measures for resolving cache misses across their infrastructure.

Using Google's Public DNS provides increased security
One of the bigger problems with publicly available resolvers is the possibility that they could be used in Denial of Service and Amplification attacks by making a small query which returns a large response. Google has taken a number of measures to protect against some of the most common attacks and monitors their resolvers carefully to ensure bad actors are not able to misuse their service. In addition to monitoring their servers for bad actors, Google Public Resolvers fully support DNSSEC which allows them to guarantee the responses they are offering are authentic and from authoritative sources.

The right answer to every query
One of the biggest reasons we suggest customers switch to Google's resolvers is that their network is set to use improperly configured resolvers. Providing correct results is one of the key benefits which Google Public DNS provides. It puts priority on returning the right answer to a query. In cases when there is a query for a non-existent or mistyped domain name, users get an NXDOMAIN response, which indicates no known response, to their query.

How to use Google Public DNS
Now that we've investigated why you might want to use Google's Public DNS let's take a look at what you need to do to use it. Configuring your settings will vary based on the operating system and device you are using. You will also likely need administrative control of your computer to change these settings, but you should be able to adjust the DNS settings for your system whereever you would adjust other network settings. Specifically, you should use the following addresses, or even just the IPv4 addresses, as your DNS servers.

Google's Public DNS IP addresses (IPv4) are:

8.8.8.8
8.8.4.4
Google's Public DNS IPv6 addresses are:

2001:4860:4860::8888
2001:4860:4860::8844
Hopefully this guide will help you avoid problems with your DNS configuration and provide you with more reliable resolution.