APNIC elearning: Reverse DNS for IPv4 and IPv6

Similar documents
Overview. Principles Creating reverse zones Setting up nameservers Reverse delegation procedures IPv6 Reverse DNS

APNIC Internet Resource Management (IRM) Tutorial. Petaling Jaya, Malaysia 24 February 2014

APNIC elearning: Requesting IP Address

Reverse DNS Delegations

DNS Concepts. APNIC 16, Seoul, Korea 19, August 2003

IPv6 Support in the DNS. Workshop Name Workshop Location, Date

DNS. Computer networks - Administration 1DV202. fredag 30 mars 12

Domain Name Server. Training Division National Informatics Centre New Delhi

ECE 4321 Computer Networks. Network Programming

IPv6 support in the DNS

APNIC IPv6 Deployment

IPv6 Support in the DNS. Workshop Name Workshop Location, Date

Copyright

- Domain Name System -

Motivation. Domain Name System (DNS) Flat Namespace. Hierarchical Namespace

Domain Name System :49:44 UTC Citrix Systems, Inc. All rights reserved. Terms of Use Trademarks Privacy Statement

DNS + DHCP. Michael Tsai 2015/04/27

Introduction to the Domain Name System

Application Protocols in the TCP/IP Reference Model

DNS & IPv6. Agenda 4/14/2009. MENOG4, 8-9 April Raed Al-Fayez SaudiNIC CITC rfayez@citc.gov.sa, DNS & IPv6.

DNS. Computer Networks. Seminar 12

Application Protocols in the TCP/IP Reference Model. Application Protocols in the TCP/IP Reference Model. DNS - Concept. DNS - Domain Name System

DNS Domain Name System

DNS : Domain Name System

Using Webmin and Bind9 to Setup DNS Sever on Linux

Understanding DNS By Robert Sterler

Understand Names Resolution

Domain Name System (DNS) Fundamentals

How to Configure the Windows DNS Server

DNS Session 4: Delegation and reverse DNS. Joe Abley AfNOG 2006 workshop

IRINN affiliation Guide

Introduction to DNS CHAPTER 5. In This Chapter

Services: DNS domain name system

Configuring DNS. Finding Feature Information

what s in a name? taking a deeper look at the domain name system mike boylan penn state mac admins conference

The Domain Name System

Local DNS Attack Lab. 1 Lab Overview. 2 Lab Environment. SEED Labs Local DNS Attack Lab 1

Application Protocols in the TCP/IP Reference Model. Application Protocols in the TCP/IP Reference Model. DNS - Domain Name System

DNS and Interface User Guide

Basic DNS Course. Module 1. DNS Theory. Ron Aitchison ZYTRAX, Inc. Page 1 of 24

DNS. DNS Fundamentals. Goals of this lab: Prerequisites: LXB, NET

An Introduction to the Domain Name System

Network Security Fundamentals

Domain Name System. Heng Sovannarith

Hostnames. HOSTS.TXT was a bottleneck. Once there was HOSTS.TXT. CSCE515 Computer Network Programming. Hierarchical Organization of DNS

Switching Your DNS WiredTree

DNS Domain Name System

Talk-101 User Guide. DNSGate

Reverse DNS considerations for IPv6

HTG XROADS NETWORKS. Network Appliance How To Guide: EdgeDNS. How To Guide

How to Configure Split DNS

Tunnel Client FAQ. Table of Contents. Version 0v5, November 2014 Revised: Kate Lance Author: Karl Auer

How To Manage Dns On An Elfiq Link Load Balancer (Link Balancer) On A Pcode (Networking) On Ipad Or Ipad (Netware) On Your Ipad On A Ipad At A Pc Or Ipa

Application and service delivery with the Elfiq idns module

Internet-Praktikum I Lab 3: DNS

How To Guide Edge Network Appliance How To Guide:

FAQ (Frequently Asked Questions)

How to Add Domains and DNS Records

Domain Name System (DNS) Session-1: Fundamentals. Ayitey Bulley

How to Configure DNS Zones

IPv6 and IPv4 Update from the RIPE NCC. Sandra Brás, Ferenc Csorba

DNS. The Root Name Servers. DNS Hierarchy. Computer System Security and Management SMD139. Root name server. .se name server. .

DNS - Domain Name System

DNS: How it works. DNS: How it works (more or less ) DNS: How it Works. Technical Seminars Spring Paul Semple psemple@rm.

Configuring the BIND name server (named) Configuring the BIND resolver Constructing the name server database files

CS3250 Distributed Systems

The Domain Name System

CSIS 3230 Computer Networking Principles, Spring 2012 Lab 7 Domain Name System (DNS)

Windows 2008 Server. Domain Name System Administración SSII

Section 1 Overview Section 2 Home... 5

Creating a master/slave DNS server combination for your Grid Infrastructure

HTG XROADS NETWORKS. Network Appliance How To Guide: DNS Delegation. How To Guide

Agenda. Network Services. Domain Names. Domain Name. Domain Names Domain Name System Internationalized Domain Names. Domain Names & DNS

Glossary of Technical Terms Related to IPv6

Domain Name System (DNS) Services

How To Get An Ipv6 Allocation On Ipv4 (Ipv4) From Ipv5) From The Ipvripe Ncc (Ip6) From A Ipvv6 Ipv2 (Ip4) To Ip

RIPE Network Coordination Centre RIPE NCC LIR Tutorial

Part 5 DNS Security. SAST01 An Introduction to Information Security Martin Hell Department of Electrical and Information Technology

How-to: DNS Enumeration

2 HDE Controller X DNS Server Manual

How to set up the Integrated DNS Server for Inbound Load Balancing

Understanding DNS (the Domain Name System)

Motivation. Users can t remember IP addresses. Implemented by library functions & servers. - Need to map symbolic names (

THE DOMAIN NAME SYSTEM DNS

APNIC elearning: Network Security Fundamentals. 20 March :30 pm Brisbane Time (GMT+10)

Applies To: Windows Server 2003, Windows Server 2003 R2, Windows Server 2003 with SP1, Windows Server 2003 with SP2

The Erado Hosted Messaging Installation Process Erado Hosted Mail Services with Domain Transfer

Internetworking with TCP/IP Unit 10. Domain Name System

Configuring a Domain to work with your Server

Domain Name System. Overview. Domain Name System. Domain Name System

DNS ActiveX Control for Microsoft Windows. Copyright Magneto Software All rights reserved

Transcription:

APNIC elearning: Reverse DNS for IPv4 and IPv6 06 OCT 2015 11:00 AM AEST Brisbane (UTC+10) Issue Date: 07 July 2015 Revision: 2.0 Introduction Presenter Sheryl Hermoso Training Officer sheryl@apnic.net Specialties: Network Security IPv6 DNS/DNSSEC Internet Resource Mgmt Reminder: Please take time to fill-up the survey 2 1

Overview What is Reverse DNS? Principles of DNS Tree Creating Reverse Zones PTR Records IPv6 Reverse Lookups Managing Reverse DNS Reverse Delegation Procedures Whois Domain Objects 3 What is Reverse DNS? Forward DNS maps names to numbers svc00.apnic.net è202.12.28.131 Reverse DNS maps numbers to names 202.12.28.131 è svc00.apnic.net 4 2

Uses of Reverse DNS Service denial That only allow access when fully reverse delegated eg. anonymous ftp Diagnostics Assisting in network troubleshooting (ex: traceroute) Spam identifications Reverse lookup to confirm the source of the email Failed lookup adds to an email s spam score 5 Reverse DNS Tree Root. Mapping numbers to names - reverse DNS net org com arpa apnic iana in-addr whois www training www 202 203 204 210 64 22 22.64.202.in-addr.arpa. ws1 ws2 6 3

Reverse DNS Tree with IPv6 Root. net org com arpa apnic iana in-addr int ip6 RFC 3152 202 203 IPv6 addresses 64 22 7 Creating Reverse Zones Same as creating a forward zone file SOA and initial NS records are the same as forward zone Create additional PTR records In addition to the forward zone files, you need the reverse zone files Ex: for a reverse zone on a 203.176.189.0/24 block, create a zone file and name it as db.203.176.189 (make it descriptive) 8 4

Start of Authority (SOA) record Domain_name. CLASS SOA hostname.domain.name. mailbox.domain.name ( Serial Number Refresh Retry Expire Minimum TTL ) Serial Number must be updated if any changes are made in the zone file Refresh how often a secondary will poll the primary server to see if the serial number for the zone has increased Retry - If a secondary was unable to contact the primary at the last refresh, wait the retry value before trying again Expire - How long a secondary will still treat its copy of the zone data as valid if it can't contact the primary. Minimum TTL - The default TTL (time-to-live) for resource records 9 TTL Time Values The right value depends on your domain Recommended time values for TLD (based on RFC 1912) Refresh 86400 (24h) Retry 7200 (2h) Expire 2592000 (30d) Min TTL 345600 (4d) For other servers optimize the values based on Frequency of changes Required speed of propagation Reachability of the primary server (and many others) 10 5

Pointer (PTR) Records Create pointer (PTR) records for each IP address 131.28.12.202.in-addr.arpa. IN PTR svc00.apnic.net. or 131 IN PTR svc00.apnic.net. 11 IPv6 Reverse Lookups PTR records Similar to the IPv4 reverse record b.a.9.8.7.6.5.0.4.0.0.0.3.0.0.0.2.0.0.0.1.0.0.0.0.0.0.0.1.2.3.4.ip6.arpa. IN PTR test.ip6.example.com. Example: reverse name lookup for a host with address 3ffe: 8050:201:1860:42::1 $ORIGIN 0.6.8.1.1.0.2.0.0.5.0.8.e.f.f.3.ip6.arpa. 1.0.0.0.0.0.0.0.0.0.0.0.2.4.0.0 14400 IN PTR host.example.com. 12 6

Reverse Zone Example $ORIGIN 1.168.192.in-addr.arpa. @ 3600 IN SOA test.company.org. ( sys\.admin.company.org. 2002021301 ; serial 1h ; refresh 30M ; retry 1W ; expiry 3600 ) ; neg. answ. ttl NS ns.company.org. NS ns2.company.org. 1 PTR gw.company.org. router.company.org. 2 PTR ns.company.org. ;auto generate: 65 PTR host65.company.org $GENERATE 65-127 $ PTR host$.company.org. 13 Managing Reverse DNS APNIC manages reverse delegation for both IPv4 and IPv6 Before you register your domain objects, you need to ensure that your reverse zones have been configured and loaded in your DNS name servers. APNIC does not host your DNS name servers or configure your reverse zone files. APNIC only delegates the authority of your reverse zones to the DNS name servers you provide through your domain objects. 14 7

Reverse Delegation Requirements /24 Delegations Address blocks should be delegated At least one name server /16 Delegations Same as /24 delegations APNIC delegates entire zone to member < /24 Delegations Not supported in the RIR level Read classless in-addr.arpa delegation RFC 2317 15 Reverse Delegation Procedures Create a whois object for the reverse zone This can be done in MyAPNIC Verify nameserver and domain set up before submitting to the database Provide the FQDN of two nameservers Provide the maintainer password Used to protect objects 16 8

APNIC & LIR Responsibilities APNIC Manage reverse delegations of address block distributed by APNIC Process requests for reverse delegation of network allocations LIR and members Be familiar with APNIC procedures Ensure that addresses are reverse-mapped Maintain nameservers for allocations Keep accurate records in the database 17 Reverse Delegation Procedures Resources > IPv4 / IPv6 > Bulk reverse delegations Input your IP address block here At least one DNS server (FQDN) Maintainer password 18 9

Whois domain object Reverse Zone 28.12.202.in-addr.arpa in-addr.arpa zone for 28.12.202.in-addr.arpa NO4-AP AIC1-AP Contacts NO4-AP cumin.apnic.net tinnie.apnic.net Nameservers tinnie.arin.net MAINT-APNIC-AP Maintainers domain: Descr: admin-c: tech-c: zone-c: nserver: nserver: nserver: mnt-by: mnt-lower: MAINT-AP-DNS changed: inaddr@apnic.net 20021023 changed: inaddr@apnic.net 20040109 changed: hm-changed@apnic.net 20091007 changed: hm-changed@apnic.net 20111208 source: APNIC 19 APNIC Helpdesk Chat 20 10

Questions Please remember to fill out the feedback form https://www.surveymonkey.com/r/ apnic-20151007-el1 Slide handouts will be available after completing the survey 21 Thank You! END OF SESSION 22 11