Infoblox’s global team of threat hunters uncovers a DNS operation with the ability to bypass traditional security measures and control the Great Firewall of China. Read about “Muddling Meerkat” and the many other threat actors discovered by Infoblox Threat Intel here.

NIOS DNS DHCP IPAM

Reply

Delegate a single record to an external DNS

New Member
Posts: 2
528     0

I wonder if anyone could assist/explain how to delegate a single record to an external DNS service.
This is what I am trying to achieve https://www.carlstalhood.com/global-server-load-balancing-gslb-netscaler-11/#dnsdelegation and I am familiar on how to perform this using AD DNS.

Followed the instructions in https://docs.infoblox.com/space/nios86/36700272/Configuring+Delegated%2C+Forward%2C+and+Stub+Zones#C...

but does not seem to work.

Any hints would be appreciated.

Re: Delegate a single record to an external DNS

[ Edited ]
Authority
Posts: 20
529     0

There is not such a thing as delegating an individual record, a delegation always hands off control for a portion of namespace to another set of servers.  That set of servers has control over that subdomain and anything below it, unless it delegates a portion to yet another set of servers.

 

The link you referenced does talk about the two general approaches for doing GSLB with external GSLB services (as opposed to integrated ones like Infoblox DNS Traffic Control (DTC)).  Historically, you could do a delegation for each GSLB object pointing to the GSLB servers or you could create a dedicated subdomain for all GSLB records and then use CNAMEs to control what records are directed to the GSLB namespace.  In my experience, the subdomain approach is a much better long-term strategy.  Once the subdomain is delegated, everything else is just record management, which means you don't need to do service restarts every time you need to add a GSLB record, which you would if you are using individual delegations.  I would highly recommend considering the subdomain approach, or to use DTC, which allows you to do GSLB directly within the domains and doesn't require any additional systems.

 

If you do want to continue on the path of doing individual delegations; however, you simply do a delegation for that name pointing to the GSLB servers.  Navigate into the domain that the delegation would fall under, switch to the "Subzones" tab, and then use the arrow next to the + to add and select "Delegation".  See the screenshot.

Screenshot 2024-06-07 at 1.58.49 PM.png

Re: Delegate a single record to an external DNS

New Member
Posts: 2
529     0

Thank you very much Ross, a very good explanation and agree with your guidance.
I am not familiar with the product but suspected that the solution might be something as you described.
Basically delegating a subdomain such as gslb.example.com and create records under that zone such as store.gslb.example.com.  And utilize CNAMEs to shorten the name.
Excellent!

Showing results for 
Search instead for 
Did you mean: 

Recommended for You