ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login
    1. Topics
    2. Tags
    3. dns
    Log in to post
    • All categories
    • J

      Move dns hosting to Cloudflare?

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion cloudflare dns
      10
      1 Votes
      10 Posts
      954 Views
      scottalanmillerS

      @Dashrender said in Move dns hosting to Cloudflare?:

      @JaredBusch said in Move dns hosting to Cloudflare?:

      @JokkeM said in Move dns hosting to Cloudflare?:

      @JaredBusch

      You have public DNS servers that are the authoritative source for your domains? - Yes
      These servers are in our datacenter and they have like ~300 zones

      By doing the "move dns hosting to CF" i would get rid of those 3 servers totally.

      Do this today. I would hate to have to run public, authoritative DNS servers.
      Just for DNS, I cannot imagine how CloudFlare would not be cheaper than running this yourself. Unless you are doing more than just DNS, CloudFlare is free.

      They have a great API for managing things at scale.

      I'm thinking the same thing - in fact, unless you've been running these servers since the mid 90's I can't see any reason why you could do that. Most registrars offered the DNS hosting as part of the cost of the domain registration. Sure they might not have had simple APIs for managing them... but damn, self hosted just seems - odd.

      It actually simplifies some things (and makes others harder.) It's not common and there are good reasons to not do it, but there are good reasons to want it, too.

    • H

      Same subdomain name internal and external i have an issue with the DNS, specifically emails

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion dns mx records email smtp
      10
      1 Votes
      10 Posts
      787 Views
      scottalanmillerS

      @huzefa22 said in Same subdomain name internal and external i have an issue with the DNS, specifically emails:

      @Dashrender when i ping mail.abc.xyz.com i don't get a reply, the SOA is the primary and the secondary domain on the local domain. i don't know if this is what you were asking.

      Regards,
      Huzefa

      Never test DNS with ping. Test with nslookup. Whether you can ping or not is a factor of many things, DNS just one of them and only sometimes. nslookup tests DNS and nothing else.

    • mroth911M

      locking down network

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion ubnt edgeos edgerouter ubiquiti networking opendns dns security
      25
      1 Votes
      25 Posts
      3k Views
      DashrenderD

      @mroth911 said in locking down network:

      so basically I am helping with my church/School , they need to connect to apple/android store. youtube. but social media sites locked down and p2p networks and anything inappropriate for k-12.

      So OpenDNS is doing the trick for now., However there is no cherry picking, and certain users need the ability to connect to facebook as well. Posting via webpage what is going on in school etc.

      Thats the situation at hand.

      They received a letter that someone on the network was downloading from BitTorrent. and it broke digital media anti-piracy law. etc. So they are naturally freaking out.

      This is something I want to setup and walk away.. I am just doing this to help them.

      Blocking Bittorrent without an application level firewall isn't that easy. Talking to the tracker happens via DNS, but talking to the other clients normally is just via IP address.

      You could block all non needed outbound ports - but again, I think Bittorrent can work over port 80 and 443, so not really that helpful.

    • JaredBuschJ

      Where do I start with replacing the whole MS AD stack

      Watching Ignoring Scheduled Pinned Locked Moved Water Closet microsoft active directory ad dhcp dns
      104
      3 Votes
      104 Posts
      13k Views
      Emad RE

      @Donahue said in Where do I start with replacing the whole MS AD stack:

      sing reservations.

      I think your knowledge of FG is not allowing you to do this, just create a new interface with the desired subnet and leave or tick DHCP option. And they you can do it what you want with it. Create an IPv4 policy to give access to internet to the new interface.

    • mlnewsM

      When a network intel provider’s domain serves fraudulent content, something is wrong

      Watching Ignoring Scheduled Pinned Locked Moved News thousandeyes security ars technica dns
      1
      1 Votes
      1 Posts
      298 Views
      No one has replied
    • dbeatoD

      Setup LetsEncrypt Certbot with CLoudFlare DNS authentication (Ubuntu)

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion nginx lets encrypt cloudflare certbot dns ubuntu 18.04
      6
      4 Votes
      6 Posts
      20k Views
      scottalanmillerS

      @aboka said in Setup LetsEncrypt Certbot with CLoudFlare DNS authentication (Ubuntu):

      hi, thanks for sharing this guide, would like to ask, what port does ppa:certbot use? im running nginx and its already using 80 & 443. i need to find a way to renew the cert when using Cloudflare as the common way(certbot renew) will not work. thank you.

      There are certbot options to use the running server (Nginx in this case.) But I agree with Jared, better to use DNS.

    • wirestyle22W

      DNS Update Issue

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion windows server 2012 r2 dns active directory
      267
      0 Votes
      267 Posts
      48k Views
      scottalanmillerS

      @JaredBusch said in DNS Update Issue:

      @scottalanmiller the issue with nslookup being useless is stupid though.

      Agreed, that's really messed up.

    • scottalanmillerS

      Handling DNS in a Single Active Directory Domain Controller Environment

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion ad dc ad dns windows windows server
      242
      0 Votes
      242 Posts
      44k Views
      scottalanmillerS

      @obsolesce said in Handling DNS in a Single Active Directory Domain Controller Environment:

      @scottalanmiller said in Handling DNS in a Single Active Directory Domain Controller Environment:

      @obsolesce said in Handling DNS in a Single Active Directory Domain Controller Environment:

      @stuartjordan said in Handling DNS in a Single Active Directory Domain Controller Environment:

      I believe the forest level with Samba can only be 2008R2 though.

      If you're not using Windows AD, what's it matter?

      If he's merging in DFS, it might. It's rare to do, but could matter.

      Oh I see, so Windows AD and other services were involved at some point.

      Depending on what you want to do, sometimes AD has to support it.

    • travisdh1T

      DNS over TLS router.

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion dns secure
      22
      1 Votes
      22 Posts
      2k Views
      wrx7mW

      The settings are
      network.trr, network.trr.mode and network.trr.uri

    • gjacobseG

      Linux Mint DNS Issue

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion linux mint dns network routing wireless wired
      3
      0 Votes
      3 Posts
      818 Views
      stacksofplatesS

      Also what's in /etc/resolve.conf?

    • travisdh1T

      DNS-over-HTTPS with Fedora based PiHole and Cloudflare

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion fedora pihole dns https
      17
      6 Votes
      17 Posts
      5k Views
      travisdh1T

      @jaredbusch said in DNS-over-HTTPS with Fedora based PiHole and Cloudflare:

      The entire concept is just stupid.
      You cannot hide from your provider.

      I'd agree with you, at least for now. This is just one small step in the right direction. It won't really make much difference until it's supported by all endpoints.

    • KellyK

      Public DNS Provider Comparison

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion dns cloudflare
      6
      2 Votes
      6 Posts
      841 Views
      scottalanmillerS

      @momurda said in Public DNS Provider Comparison:

      Unlike FB, CloudFare actually makes products and sells them to customers.

      An example: MangoLassi is a commercial CloudFlare customer. Without CF, we'd never be able to push the 200 million hits a month we sometimes take here!

    • JaredBuschJ

      Add porn blocking to your Pi-hole

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion pi-hole content filtering dns
      19
      11 Votes
      19 Posts
      73k Views
      JaredBuschJ

      @gap579137 said in Add porn blocking to your Pi-hole:

      We have a very good list at [site redacted] if you would like to at it to you lists.

      Interesting concept..
      491adb7c-e991-4b5a-bb1c-0ff38aee2d06-image.png

    • mlnewsM

      CloudFlare Launches Privacy First DNS Service

      Watching Ignoring Scheduled Pinned Locked Moved News cloudflare dns 1.1.1.1 privacy
      62
      3 Votes
      62 Posts
      9k Views
      A

      Maybe they were using 1.1.1.1 as a null route?

    • J

      Urgent: How to fix this FreePBX Repo Access Issue?

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion freepbx asterisk linux networking dns
      22
      0 Votes
      22 Posts
      4k Views
      scottalanmillerS

      @jimmy_k said in Urgent: How to fix this FreePBX Repo Access Issue?:

      @jimmy_k Well, I just fixed it
      I modified etc/resolv.conf by putting this

      nameserver same as DNS1
      nameserver same as DNS2

      That's what that script is supposed to do. If you did this, it means either you never activated the script or it is broken and will stop working again.

    • JaredBuschJ

      What does Quad9 do the Pihole does not

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion quad9 dns security pi-hole
      8
      2 Votes
      8 Posts
      2k Views
      thwrT

      @scottalanmiller said in What does Quad9 do the Pihole does not:

      @thwr said in What does Quad9 do the Pihole does not:

      @jaredbusch said in What does Quad9 do the Pihole does not:

      @thwr said in What does Quad9 do the Pihole does not:

      Just from reading I would say he's using Quad9 as upstream DNS for his PiHole (which is used by clients)

      I know that. I mean, what is the service Quad9 doing.

      It's another "privacy" friendly DNS driven by IBM, Packet Clearing House (PCH) and Global Cyber Alliance (GCA). Placed as an alternative to Google's DNS

      "Privacy friendly" is what we are worried about. It's from the US gov't so we really don't trust it.

      I'm sure you've noticed the quotes around "privacy".

    • mlnewsM

      Quad9 DNS Malicious Domain Blocking Service

      Watching Ignoring Scheduled Pinned Locked Moved News quad9 dns security ars technica
      46
      2 Votes
      46 Posts
      6k Views
      ObsolesceO

      @tim_g said in Quad9 DNS Malicious Domain Blocking Service:

      I stopped testing Quad9 on my computer. I've been having some weird issues with GitLab errors on the website. As soon as I plugged in Google's DNS, it worked.

      But then again, a refresh or two got it working again while I was still using Quad9.

      I'll update later to report if any issue like that returns now that I'm using Google on my computer.

      Nope, was not Quad9 related.

      I think it's some kind of timeout I never noticed before or GitLab is having issues.

    • mlnewsM

      Home Network Setup

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion xp dhcp dns home lab xenserver kvm ubiquiti virtualization sophos linux untangle
      88
      2 Votes
      88 Posts
      12k Views
      jmooreJ

      @scottalanmiller said in Home Network Setup:

      @jmoore said in Home Network Setup:

      @scottalanmiller said in Home Network Setup:

      @dashrender said in Home Network Setup:

      The whole crux of my ask was - the desire to buy as few Windows Server CALs as possible.

      This is unrelated to the question asked, though.

      you know i have noticed you and dash really communicate differently. not good or bad, just different. then you both have trouble understanding the other. from the many threads i have read with you two, that is the common theme i have seen.

      I'd assume part of it is that I am highly literal. That tends to be a root of many communications issues for me in general.

      yeah i think your right you are literal. i had to adjust my communication with you. that was my fault though, i am used to having to be so unliteral with my users because i would lose them that i got into that bad habit lol. i know for me, i was not explaining my thoughts in a well laid out way and that made me harder to understand and threw you off. did i do better that time?

    • NerdyDadN

      How to choose public DNS provider for an ISP

      Watching Ignoring Scheduled Pinned Locked Moved IT Business isp wisp dns
      33
      1 Votes
      33 Posts
      6k Views
      JaredBuschJ

      @nerdydad said in How to choose public DNS provider for an ISP:

      or should I give them something that is more privacy focused but might also restrict their access to the internet.

      But OpenDNS does nothing of the sort. It is a pubic open DNS service available for anyone to use.

    • A

      Pi Hole

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion pi-hole dns security
      135
      5 Votes
      135 Posts
      24k Views
      JaredBuschJ

      EchoDot came back hard.

      I disabled the pi-hole for 5 minutes (setting in the menu on the left) and poof. it is happy again.

      0_1523583914500_7ec4ae68-6fbc-466c-b499-3cad488459ef-image.png

      0_1523583888016_b5fd7e49-7c6a-4d40-9498-e7362394b34e-image.png

    • 1
    • 2
    • 3
    • 4
    • 5
    • 6
    • 3 / 6