13.4 DNS Outsourcing

   

Managing DNS security can be a headache , especially for large organizations. For companies that do not have the staff to manage and support large zone files, outsourcing may be a better alternative.

Some companies, like UltraDNS, Nominum, and easyDNS, offer managed DNS, while other companies, such as Men & Mice, will set up DNS service in-house. The services can range from having the company's team manage and support some, or all, aspects of an organization's in-house DNS services to a fully managed off-site DNS service.

There are some obvious advantages to this type of service. Outsourcing DNS frees up in-house network administrators so they do not have to worry about the day-to-day maintenance of DNS servers, and an organization can quickly have a scalable DNS solution that is redundant and secure.

DNS outsourcing has been around for a long time. Most organizations that do not have the expertise to manage their own DNS let their ISP, or even their registrar, manage their zone files. While these solutions are adequate for smaller companies, midsize and larger companies should consider a dedicated outsourced DNS provider. Many ISPs and registrars are not equipped to handle hundreds of thousands of request per day to a single domain. ISPs and registrars are not always equipped to handle frequent updates to zone files as well. If your organization makes several DNS changes each week, or even each day, a DNS outsourcing provider may be the best solution.

As with other outsourcing providers, managed DNS providers should be quizzed thoroughly about their security precautions and the types of guarantees they provide. [2]

[2] You are welcome to send them a copy of this book to verify they follow all procedures listed in this chapter.

Managed DNS providers not only provide authoritative DNS services, they can also provide outsourced caching DNS. Again, this may be useful for companies that do not want to manage caching DNS servers in-house. However, for a large organization, switching caching DNS from an internal server to an external server can cause significant traffic changes. The impact of those traffic changes should be carefully weighed against the benefits of outsourcing caching DNS.

   


The Practice of Network Security. Deployment Strategies for Production Environments
The Practice of Network Security: Deployment Strategies for Production Environments
ISBN: 0130462233
EAN: 2147483647
Year: 2002
Pages: 131
Authors: Allan Liska

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net