Configuring Dynamic DNS



Similar documents
DHCP and DNS Services

Dynamic DNS Support for Cisco IOS Software

IPv6 in Axis Video Products

Introduction to the Domain Name System

How To - Configure Virtual Host using FQDN How To Configure Virtual Host using FQDN

Lab Configuring the PIX Firewall as a DHCP Server

HREP Series DVR DDNS Configuration Application Note

Securing Networks with PIX and ASA

Quick Note 53. Ethernet to W-WAN failover with logical Ethernet interface.

Savvius Insight Initial Configuration

Services. Vyatta System. REFERENCE GUIDE DHCP DHCPv6 DNS Web Caching LLDP VYATTA, INC.

Configuring NetFlow Secure Event Logging (NSEL)

Adding an Extended Access List

Use Domain Name System and IP Version 6

Application Note. SIP Domain Management

Networking Domain Name System

IPv6.marceln.org.

Hosting more than one FortiOS instance on. VLANs. 1. Network topology

Configuring Switch Ports and VLAN Interfaces for the Cisco ASA 5505 Adaptive Security Appliance

Configuring Windows Server Clusters

PineApp Surf-SeCure Quick

IM and Presence Service Network Setup

Network Working Group. Category: Standards Track October 2006

Configuring WAN Failover & Load-Balancing

- The PIX OS Command-Line Interface -

Domain Name System :49:44 UTC Citrix Systems, Inc. All rights reserved. Terms of Use Trademarks Privacy Statement

Lab 5 Explicit Proxy Performance, Load Balancing & Redundancy

Configuring Switch Ports and VLAN Interfaces for the Cisco ASA 5505 Adaptive Security Appliance

Global Server Load Balancing (GSLB) Concepts

Date 07/05/ :20:22. CENTREL Solutions. Author. Version Product XIA Configuration Server [ ]

Smart Tips. Enabling WAN Load Balancing. Key Features. Network Diagram. Overview. Featured Products. WAN Failover. Enabling WAN Load Balancing Page 1

M2M Series Routers. Virtual Router Redundancy Protocol (VRRP) Configuration Whitepaper

Configuring PA Firewalls for a Layer 3 Deployment

Configuring Sonus SBC 1000/2000. with. Rogers Business Solution (RBS) SIP Trunking Service. Application Note

Technical Note. vsphere Deployment Worksheet on page 2. Express Configuration on page 3. Single VLAN Configuration on page 5

Dynamic DNS Support for Cisco IOS Software

Chapter 2 Connecting the FVX538 to the Internet

Blue Coat Security First Steps Solution for Deploying an Explicit Proxy

Firewall Load Balancing

NETWORK SETUP GLOSSARY

1 Data information is sent onto the network cable using which of the following? A Communication protocol B Data packet

What communication protocols are used to discover Tesira servers on a network?

Chapter 25 Domain Name System Copyright The McGraw-Hill Companies, Inc. Permission required for reproduction or display.

Configuring Basic Settings

Government of Canada Managed Security Service (GCMSS) Annex A-1: Statement of Work - Firewall

Configuring Basic Settings

Configuration Notes 0215

Chapter 6 Configuring the SSL VPN Tunnel Client and Port Forwarding

1 PC to WX64 direction connection with crossover cable or hub/switch

Installation of the On Site Server (OSS)

Configuring DHCP Snooping

Configuring Basic Settings

Cisco ASA, PIX, and FWSM Firewall Handbook

PowerLink Bandwidth Aggregation Redundant WAN Link and VPN Fail-Over Solutions

CYAN SECURE WEB APPLIANCE. User interface manual

Configuring Failover. Understanding Failover CHAPTER

Configuring IP Addressing and Services

IP Services REFERENCE GUIDE. VYATTA, INC. Vyatta System SSH. DHCP DNS Web Caching. Title

Using Remote Desktop Software with the LAN-Cell 3

HRG Performance Series DVR DDNS Support Application Note (DynDNS)

How to configure WFS (Windows File Sharing ) Acceleration on SonicWALL WAN Acceleration Appliances

SonicWALL DHCP Server Enhancements in SonicOS Enhanced 4.0

Cisco ASA 5500-X Series ASA 5512-X, ASA 5515-X, ASA 5525-X, ASA 5545-X, and ASA 5555-X

Configuring NetFlow Secure Event Logging (NSEL)

Local DNS Attack Lab. 1 Lab Overview. 2 Lab Environment. SEED Labs Local DNS Attack Lab 1

How to Configure the Windows DNS Server

Using Remote Desktop Software with the LAN-Cell

What is VLAN Routing?

2. IP Networks, IP Hosts and IP Ports

ASA 8.3 and Later: Enable FTP/TFTP Services Configuration Example

VoIP CONFIGURATION GUIDE FOR MULTI-LOCATION NETWORKS

THINKTEL COMMUNICATIONS DIGIUM G100/G200 PRI OVER IP SIP TRUNKING

Implementing Core Cisco ASA Security (SASAC)

NAS 321 Hosting Multiple Websites with a Virtual Host

How do I configure multi-wan in Routing Table mode?

How To Set Up A Pploe On A Pc Orca On A Ipad Orca (Networking) On A Macbook Orca 2.5 (Netware) On An Ipad 2.2 (Netrocessor

How to Add Domains and DNS Records

Time Warner ITSP Setup Guide

BR Load Balancing Router. Manual

Cisco PIX. Upgrade-Workshop PixOS 7. Dipl.-Ing. Karsten Iwen CCIE #14602 (Security)

NETGEAR ProSAFE WC9500 High Capacity Wireless Controller

Recommendations for dealing with fragmentation in DNS(SEC)

NetVanta 7060/7100 Configuration Checklist

DHCP Server. Heng Sovannarith

Document ID: Introduction

Configuring DNS. Finding Feature Information

Chapter 4 Customizing Your Network Settings

Using a VPN with CentraLine AX Systems

Cisco Expressway Basic Configuration

Networking Domain Name System

Intel Entry Storage System SS4200-E Active Directory Implementation and Troubleshooting

Astaro Deployment Guide High Availability Options Clustering and Hot Standby

Configuring Failover

Domain Name System (DNS) Services

Network Load Balancing

Configuring the Edgewater 4550 for use with the Bluestone Hosted PBX

Basic IPv6 WAN and LAN Configuration

Send document comments to

Transcription:

9 CHAPTER This chapter describes how to configure DDNS update methods, and includes the following topics: Information about DDNS, page 9-1 Licensing Requirements for DDNS, page 9-2 Guidelines and Limitations, page 9-2 Configuring DDNS, page 9-2 Configuration Examples for DDNS, page 9-3 DDNS Monitoring Commands, page 9-6 Feature History for DDNS, page 9-6 Information about DDNS DDNS update integrates DNS with DHCP. The two protocols are complementary: DHCP centralizes and automates IP address allocation; DDNS update automatically records the association between assigned addresses and hostnames at predefined intervals. DDNS allows frequently changing address-hostname associations to be updated frequently. Mobile hosts, for example, can then move freely on a network without user or administrator intervention. DDNS provides the necessary dynamic update and synchronization of the name-to-address mapping and address-to-name mapping on the DNS server. To configure the DNS server for other uses, see the Configuring the DNS Server section on page 7-11. To configure DHCP, see the Configuring a DHCP Server section on page 8-2. EDNS allows DNS requesters to advertise the size of their UDP packets and facilitates the transfer of packets larger than 512 octets. When a DNS server receives a request over UDP, it identifies the size of the UDP packet from the OPT resource record (RR) and scales its response to contain as many resource records as are allowed in the maximum UDP packet size specified by the requester. The size of the DNS packets can be up to 4096 bytes for BIND or 1280 bytes for the Windows 2003 DNS Server. Several additional message-length maximum commands are available: The existing global limit: message-length maximum 512 A client or server specific limit: message-length maximum client 4096 The dynamic value specified in the OPT RR field: message-length maximum client auto If the three commands are present at the same time, the adaptive security appliance enforces the minimum of the three specified values. 9-1

Licensing Requirements for DDNS Chapter 9 Licensing Requirements for DDNS Table 9-1 shows the licensing requirements for DDNS. Table 9-1 Licensing Requirements Model All models License Requirement Base License. Guidelines and Limitations Failover Guidelines Supports Active/Active and Active/Standby failover. Firewall Mode Guidelines Supported in routed firewall mode. Context Mode Guidelines Supported in single and multiple context modes. Supported in transparent mode for the DNS Client pane. IPv6 Guidelines Supports IPv6. Configuring DDNS This section describes examples for configuring the adaptive security appliance to support Dynamic DNS. DDNS update integrates DNS with DHCP. The two protocols are complementary DHCP centralizes and automates IP address allocation, while dynamic DNS update automatically records the association between assigned addresses and hostnames. When you use DHCP and dynamic DNS update, this configures a host automatically for network access whenever it attaches to the IP network. You can locate and reach the host using its permanent, unique DNS hostname. Mobile hosts, for example, can move freely without user or administrator intervention. DDNS provides address and domain name mapping so that hosts can find each other, even though their DHCP-assigned IP addresses change frequently. The DDNS name and address mapping is held on the DHCP server in two resource records: the A RR includes the name-to I- address mapping, while the PTR RR maps addresses to names. Of the two methods for performing DDNS updates the IETF standard defined by RFC 2136 and a generic HTTP method the adaptive security appliance supports the IETF method in this release. The two most common DDNS update configurations are the following: The DHCP client updates the A RR, while the DHCP server updates the PTR RR. The DHCP server updates both the A RR and PTR RR. 9-2

Chapter 9 Configuration Examples for DDNS In general, the DHCP server maintains DNS PTR RRs on behalf of clients. Clients may be configured to perform all desired DNS updates. The server may be configured to honor these updates or not. To update the PTR RR, the DHCP server must know the FQDN of the client. The client provides an FQDN to the server using a DHCP option called Client FQDN. Configuration Examples for DDNS The following examples present five common scenarios: Example 1: Client Updates Both A and PTR RRs for Static IP Addresses, page 9-3 Example 2: Client Updates Both A and PTR RRs; DHCP Server Honors Client Update Request; FQDN Provided Through Configuration, page 9-3 Example 3: Client Includes FQDN Option Instructing Server Not to Update Either RR; Server Overrides Client and Updates Both RRs., page 9-4 Example 4: Client Asks Server To Perform Both Updates; Server Configured to Update PTR RR Only; Honors Client Request and Updates Both A and PTR RR, page 9-5 Example 5: Client Updates A RR; Server Updates PTR RR, page 9-5 Example 1: Client Updates Both A and PTR RRs for Static IP Addresses The following example shows how to configure the client to request that it update both A and PTR resource records for static IP addresses. To define a DDNS update method called ddns-2 that requests that the client update both the A RR and PTR RR, enter the following commands: hostname(ddns-update-method)# ddns both To associate the method ddns-2 with the eth1 interface, enter the following commands: hostname(ddns-update-method)# interface eth1 hostname(config-if)# ddns update ddns-2 hostname(config-if)# ddns update hostname asa.example.com To configure a static IP address for eth1, enter the following command: hostname(config-if)# ip address 10.0.0.40 255.255.255.0 Example 2: Client Updates Both A and PTR RRs; DHCP Server Honors Client Update Request; FQDN Provided Through Configuration The following example shows how to configure the DHCP client to request that it update both the A and PTR RRs, and the DHCP server to honor these requests. 9-3

Configuration Examples for DDNS Chapter 9 Step 4 To configure the DHCP client to request that the DHCP server perform no updates, enter the following command: hostname(config)# dhcp-client update dns server none To create a DDNS update method named ddns-2 on the DHCP client that requests that the client perform both A and PTR updates, enter the following commands: hostname(ddns-update-method)# ddns both To associate the method named ddns-2 with the adaptive security appliance interface named Ethernet0, and enable DHCP on the interface, enter the following commands: hostname(ddns-update-method)# interface Ethernet0 hostname(if-config)# ddns update ddns-2 hostname(if-config)# ddns update hostname asa.example.com hostname(if-config)# ip address dhcp To configure the DHCP server, enter the following command: hostname(if-config)# dhcpd update dns Example 3: Client Includes FQDN Option Instructing Server Not to Update Either RR; Server Overrides Client and Updates Both RRs. The following example shows how to configure the DHCP client to include the FQDN option that instruct the DHCP server not to honor either the A or PTR updates. The example also shows how to configure the server to override the client request. As a result, the client does not perform any updates. Step 4 To configure the update method named ddns-2 to request that it make both A and PTR RR updates, enter the following commands: hostname(ddns-update-method)# ddns both To assign the DDNS update method named ddns-2 on interface Ethernet0 and provide the client hostname (asa), enter the following commands: hostname(ddns-update-method)# interface Ethernet0 hostname(if-config)# ddns update ddns-2 hostname(if-config)# ddns update hostname asa.example.com To enable the DHCP client feature on the interface, enter the following commands: hostname(if-config)# dhcp client update dns server none hostname(if-config)# ip address dhcp To configure the DHCP server to override the client update requests, enter the following command: hostname(if-config)# dhcpd update dns both override 9-4

Chapter 9 Configuration Examples for DDNS Example 4: Client Asks Server To Perform Both Updates; Server Configured to Update PTR RR Only; Honors Client Request and Updates Both A and PTR RR The following example shows how to configure the server to perform only PTR RR updates by default. However, the server honors the client request that it perform both A and PTR updates. The server also forms the FQDN by appending the domain name (example.com) to the hostname that the client (asa) has provided. To configure the DHCP client on interface Ethernet0, enter the following commands: hostname(config)# interface Ethernet0 hostname(config-if)# dhcp client update dns both hostname(config-if)# ddns update hostname asa To configure the DHCP server, enter the following commands: hostname(config-if)# dhcpd update dns hostname(config-if)# dhcpd domain example.com Example 5: Client Updates A RR; Server Updates PTR RR The following example shows how to configure the client to update the A resource record and how to configure the server to update the PTR records. Also, the client uses the domain name from the DHCP server to form the FQDN. To define the DDNS update method named ddns-2, enter the following commands: hostname(ddns-update-method)# ddns To configure the DHCP client for interface Ethernet0 and assign the update method to the interface, enter the following commands: hostname(ddns-update-method)# interface Ethernet0 hostname(config-if)# dhcp client update dns hostname(config-if)# ddns update ddns-2 hostname(config-if)# ddns update hostname asa To configure the DHCP server, enter the following commands: hostname(config-if)# dhcpd update dns hostname(config-if)# dhcpd domain example.com 9-5

DDNS Monitoring Commands Chapter 9 DDNS Monitoring Commands To monitor DDNS, enter one of the following commands: Command show running-config ddns Purpose Shows the current DDNS configuration. show running-config dns server-group Shows the current DNS server group status. Feature History for DDNS Table 9-2 lists the release history for this feature. Table 9-2 Feature History for DDNS Feature Name Releases Feature Information DDNS 7.0(1) This feature was introduced. The following commands were introduced: ddns, ddns update, dhcp client update dns, dhcpd update dns, show running-config ddns, and show running-config dns server-group. 9-6