SlideShare una empresa de Scribd logo
1 de 14
Descargar para leer sin conexión
1
• November 15th 2016
• An overview of the Domain Name System, resources,
records, name resolution and name servers.
DNS Webinar Series
• January 17th 2017
• An in-depth view on how to monitor and alert on DNS
availability, response time and record mappings.
Intro to DNS
Monitoring DNS
Records and Servers
• December 13th 2016
• Tips and examples covering DNS hijacking and DDoS
attacks on DNS infrastructure.
DNS Security
2
About ThousandEyes
ThousandEyes delivers visibility into every network your organization relies on.
Founded by network
experts; strong
investor backing
Relied on for
critical operations by
leading enterprises
Recognized as
an innovative
new approach
31 Fortune 500
5 top 5 SaaS Companies
4 top 6 US Banks
3
• The Domain Name System (DNS) is a helper system for IP.
• DNS is:
• A naming hierarchy for the Internet
• A directory service to translate (resolve) these names to IP addresses
• A protocol to perform name resolution
• You can think of DNS as a phone book for the Internet, helping you
look up IP addresses for a specific name.
The Domain Name System
4
• Domain names provide flexibility and human readability to the Internet
Protocol.
• Domain names used in URLs and email addresses (e.g.
www.google.com) are easier for humans to remember than IP
addresses.
• In addition, network operators may want to switch IP addresses
without having to change the domain name.
• And network operators may want to have multiple IP addresses
assigned to a specific domain name to, for example, serve content
from multiple locations.
Why DNS Exists
5
There are many DNS record types that store domain name data. Here
are 5 commonly used record types:
• A - IPv4 address
• AAAA - IPv6 address
• MX - Email server
• NS - Name server
• CNAME – Alias to another
domain name
A DNS record has a Time-to-Live (TTL) that specifies, in seconds, how
long it can be cached by a name server. Once it expires, the name server
must query for an updated record.
DNS Resources and Records
6
• Clients use DNS to resolve a domain name to an IP address. Name
servers store DNS records and respond to domain name queries.
• Many clients use a recursive name server located in their network to
do work on their behalf. If this domain is unknown to the recursive
server, it can start at the root. Each name server will provide the most
specific answer it can. The recursive server will iterate through the
DNS hierarchy of zones to find an authoritative name server that
can answer the query.
Name Resolution
Client
(aka resolver)
Recursive server
(ISP, company, public DNS)
Root server
a.root-servers.net
TLD server
a.gtld-servers.net
Authoritative server
ns2.google.com
7
• Recursive name servers make recursive queries on behalf of DNS
clients. They typically exist within ISPs, enterprise networks and public
DNS servers (e.g. Google public DNS 8.8.8.8).
• Many recursive servers only respond to queries from within their own
network. Some, called open resolvers, will respond to queries from
any source.
• Most recursive servers also cache DNS records, which are valid for the
length of the TTL.
Recursive Name Servers
Client
(aka resolver)
Recursive server
(ISP, company, public DNS)
Root server
a.root-servers.net
TLD server
a.gtld-servers.net
Authoritative server
ns2.google.com
Query: www.google.com
8
• There are 13 root name servers that sit atop the DNS hierarchy and
are hard coded into any application that uses DNS. These root name
servers maintain a list of the top-level domain servers (.com, .uk,
.net, etc.).
• The answers provided by root and TLD name servers contain the name
servers for the next known subdomain.
Root and TLD Name Servers
Client
(aka resolver)
Recursive server
(ISP, company, public DNS)
Root server
a.root-servers.net
TLD server
a.gtld-servers.net
Authoritative server
ns2.google.com
Query: www.google.com
Answer: a.gtld-servers.net
Query: www.google.com
Answer: ns2.google.com
9
• Authoritative name servers have authority to answer queries from
other name servers or from DNS clients. The DNS records in an
authoritative name server are maintained by domain administrator.
• A set of authoritative name servers are assigned for each zone. These
may be maintained by the organization itself, or by an external
company (UltraDNS, Akamai, Dyn, etc). Many organizations will split
name servers between multiple providers for redundancy.
Authoritative Name Servers
Recursive server
(ISP, company,
public DNS)
Root server
a.root-servers.net
TLD server
a.gtld-servers.net
Authoritative server
ns2.google.com
Query: www.google.com
Answer: 172.217.2.46
Answer: 172.217.2.46
10
Why Monitor DNS
Record
Misconfiguration
Server or Network
FailureVendor Availability
DNSSEC Expiration Cache PoisoningDDoS Attacks
11
Monitor App & Network Connectivity Anywhere
Managed DNS
Provider
Internet
1 On-Premises DNS
Local caching resolvers
and self-hosted DNS
2 Hosted DNS
Authoritative, TLD and
Root Name Servers
Access
Networks
Cloud Agents
Enterprise
Agents
Branch
Data
Center
12
• ns
• @
• +trace
• +dnssec
• +norec
ThousandEyes Approach to DNS Monitoring
• Authoritative and
caching server
network
• Routing metrics
DIG-like Features And Correlation
• Store, save,
share, baseline,
alert
With Analysis
Enterprise
Vendor
13
See what you’re missing.
Watch the webinar:
https://www.thousandeyes.com/resources/intro-to-dns-webinar

Más contenido relacionado

La actualidad más candente (20)

DNS Record
DNS RecordDNS Record
DNS Record
 
Domain name system
Domain name systemDomain name system
Domain name system
 
Dns ppt
Dns pptDns ppt
Dns ppt
 
Presentation on dns
Presentation on dnsPresentation on dns
Presentation on dns
 
DNS ( Domain Name System)
DNS ( Domain Name System)DNS ( Domain Name System)
DNS ( Domain Name System)
 
Dns server
Dns serverDns server
Dns server
 
Dns presentation
Dns presentationDns presentation
Dns presentation
 
Dhcp ppt
Dhcp pptDhcp ppt
Dhcp ppt
 
Domain name system
Domain name systemDomain name system
Domain name system
 
Dns ppt
Dns pptDns ppt
Dns ppt
 
Basics about IP address, DNS and DHCP.
Basics about IP address, DNS and DHCP.Basics about IP address, DNS and DHCP.
Basics about IP address, DNS and DHCP.
 
Domain name server
Domain name serverDomain name server
Domain name server
 
Dns(Domain name system)
Dns(Domain name system)Dns(Domain name system)
Dns(Domain name system)
 
Dns name resolution process
Dns name resolution processDns name resolution process
Dns name resolution process
 
Domain name system
Domain name systemDomain name system
Domain name system
 
DNS(Domain Name System)
DNS(Domain Name System)DNS(Domain Name System)
DNS(Domain Name System)
 
DHCP
DHCPDHCP
DHCP
 
Dns 2
Dns 2Dns 2
Dns 2
 
Dns server
Dns server Dns server
Dns server
 
Chapter 29 Domain Name System.ppt
Chapter 29 Domain Name System.pptChapter 29 Domain Name System.ppt
Chapter 29 Domain Name System.ppt
 

Destacado

Paket ambassador
Paket ambassadorPaket ambassador
Paket ambassador
Aya Aya
 
добрые советы 5
добрые советы   5добрые советы   5
добрые советы 5
Usman Suleymanov
 
чилик и коларик шевченко
чилик и коларик шевченкочилик и коларик шевченко
чилик и коларик шевченко
chilik
 
New niagasatu presentation
New niagasatu presentationNew niagasatu presentation
New niagasatu presentation
Aya Aya
 

Destacado (13)

Domain Name System
Domain Name SystemDomain Name System
Domain Name System
 
Optimizing Network Connectivity to your Data Center
Optimizing Network Connectivity to your Data CenterOptimizing Network Connectivity to your Data Center
Optimizing Network Connectivity to your Data Center
 
Paket ambassador
Paket ambassadorPaket ambassador
Paket ambassador
 
Using Data to Determine Where to Build a New Data Center at Shutterstock from...
Using Data to Determine Where to Build a New Data Center at Shutterstock from...Using Data to Determine Where to Build a New Data Center at Shutterstock from...
Using Data to Determine Where to Build a New Data Center at Shutterstock from...
 
добрые советы 5
добрые советы   5добрые советы   5
добрые советы 5
 
чилик и коларик шевченко
чилик и коларик шевченкочилик и коларик шевченко
чилик и коларик шевченко
 
Benchmarking-Public-Procurement-2017
Benchmarking-Public-Procurement-2017Benchmarking-Public-Procurement-2017
Benchmarking-Public-Procurement-2017
 
New niagasatu presentation
New niagasatu presentationNew niagasatu presentation
New niagasatu presentation
 
Endpoint Agent Part 3: LAN, Wireless, Gateways and Proxies
Endpoint Agent Part 3: LAN, Wireless, Gateways and ProxiesEndpoint Agent Part 3: LAN, Wireless, Gateways and Proxies
Endpoint Agent Part 3: LAN, Wireless, Gateways and Proxies
 
Harmonization of inter-cultural inter-religious and inter-ethnic relations: t...
Harmonization of inter-cultural inter-religious and inter-ethnic relations: t...Harmonization of inter-cultural inter-religious and inter-ethnic relations: t...
Harmonization of inter-cultural inter-religious and inter-ethnic relations: t...
 
пожар
пожарпожар
пожар
 
город
городгород
город
 
Optimizing AS Paths
Optimizing AS PathsOptimizing AS Paths
Optimizing AS Paths
 

Similar a Intro to DNS

Chapter4 configuringandmanagingthednsserverrole-140520003253-phpapp01
Chapter4 configuringandmanagingthednsserverrole-140520003253-phpapp01Chapter4 configuringandmanagingthednsserverrole-140520003253-phpapp01
Chapter4 configuringandmanagingthednsserverrole-140520003253-phpapp01
velimamedov
 
Chapter 4 configuring and managing the dns server role
Chapter 4   configuring and managing the dns server roleChapter 4   configuring and managing the dns server role
Chapter 4 configuring and managing the dns server role
Luis Garay
 
Domain name system advanced power point presentation
Domain name system advanced power point presentationDomain name system advanced power point presentation
Domain name system advanced power point presentation
rituchouhan1508
 

Similar a Intro to DNS (20)

Domain name system
Domain name systemDomain name system
Domain name system
 
Computer Networks Module 1 - part 2.pdf
Computer Networks Module 1 - part 2.pdfComputer Networks Module 1 - part 2.pdf
Computer Networks Module 1 - part 2.pdf
 
Domain Name System Explained
Domain Name System Explained Domain Name System Explained
Domain Name System Explained
 
Dns1111111111
Dns1111111111Dns1111111111
Dns1111111111
 
Chapter4 configuringandmanagingthednsserverrole-140520003253-phpapp01
Chapter4 configuringandmanagingthednsserverrole-140520003253-phpapp01Chapter4 configuringandmanagingthednsserverrole-140520003253-phpapp01
Chapter4 configuringandmanagingthednsserverrole-140520003253-phpapp01
 
DNS(In_Linux).pptx
DNS(In_Linux).pptxDNS(In_Linux).pptx
DNS(In_Linux).pptx
 
Monitoring DNS Records and Servers
Monitoring DNS Records and ServersMonitoring DNS Records and Servers
Monitoring DNS Records and Servers
 
Domainnamesystem
DomainnamesystemDomainnamesystem
Domainnamesystem
 
How DNS works and How to secure it: An Introduction
How DNS works and How to secure it: An IntroductionHow DNS works and How to secure it: An Introduction
How DNS works and How to secure it: An Introduction
 
DNS - Jaringan Komputer
DNS - Jaringan KomputerDNS - Jaringan Komputer
DNS - Jaringan Komputer
 
Chapter 4 configuring and managing the dns server role
Chapter 4   configuring and managing the dns server roleChapter 4   configuring and managing the dns server role
Chapter 4 configuring and managing the dns server role
 
Domain name system advanced power point presentation
Domain name system advanced power point presentationDomain name system advanced power point presentation
Domain name system advanced power point presentation
 
Domain Name System and Dynamic Host Configuration Protocol.pptx
Domain Name System and Dynamic Host Configuration Protocol.pptxDomain Name System and Dynamic Host Configuration Protocol.pptx
Domain Name System and Dynamic Host Configuration Protocol.pptx
 
Lecture 5- url-dns
Lecture  5- url-dnsLecture  5- url-dns
Lecture 5- url-dns
 
23rd PITA AGM and Conference: DNS Security - A holistic view
23rd PITA AGM and Conference: DNS Security - A holistic view 23rd PITA AGM and Conference: DNS Security - A holistic view
23rd PITA AGM and Conference: DNS Security - A holistic view
 
Domain Name System (DNS) - Domain Registration and Website Hosting Basics
Domain Name System (DNS) - Domain Registration and Website Hosting BasicsDomain Name System (DNS) - Domain Registration and Website Hosting Basics
Domain Name System (DNS) - Domain Registration and Website Hosting Basics
 
DNS
DNSDNS
DNS
 
CSE dns ppt.pptx
CSE dns ppt.pptxCSE dns ppt.pptx
CSE dns ppt.pptx
 
Dns
DnsDns
Dns
 
Presentation2.pptx
Presentation2.pptxPresentation2.pptx
Presentation2.pptx
 

Más de ThousandEyes

Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
ThousandEyes
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
ThousandEyes
 

Más de ThousandEyes (20)

How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesAssure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
New ThousandEyes Product Features and Release Highlights: March 2024
New ThousandEyes Product Features and Release Highlights: March 2024New ThousandEyes Product Features and Release Highlights: March 2024
New ThousandEyes Product Features and Release Highlights: March 2024
 
EMEA What is ThousandEyes? Webinar
EMEA What is ThousandEyes? WebinarEMEA What is ThousandEyes? Webinar
EMEA What is ThousandEyes? Webinar
 
Outage Analysis: March 5th/6th 2024 Meta, Comcast, and LinkedIn
Outage Analysis: March 5th/6th 2024 Meta, Comcast, and LinkedInOutage Analysis: March 5th/6th 2024 Meta, Comcast, and LinkedIn
Outage Analysis: March 5th/6th 2024 Meta, Comcast, and LinkedIn
 
Assure Patient and Clinician Digital Experiences with ThousandEyes for Health...
Assure Patient and Clinician Digital Experiences with ThousandEyes for Health...Assure Patient and Clinician Digital Experiences with ThousandEyes for Health...
Assure Patient and Clinician Digital Experiences with ThousandEyes for Health...
 
AMER Introduction to ThousandEyes Webinar
AMER Introduction to ThousandEyes WebinarAMER Introduction to ThousandEyes Webinar
AMER Introduction to ThousandEyes Webinar
 
New ThousandEyes Product Features and Release Highlights: February 2024
New ThousandEyes Product Features and Release Highlights: February 2024New ThousandEyes Product Features and Release Highlights: February 2024
New ThousandEyes Product Features and Release Highlights: February 2024
 
The Top Outages of 2023: Analyses and Takeaways
The Top Outages of 2023: Analyses and TakeawaysThe Top Outages of 2023: Analyses and Takeaways
The Top Outages of 2023: Analyses and Takeaways
 
Enhancing SaaS Performance: A Hands-on Workshop for Partners
Enhancing SaaS Performance: A Hands-on Workshop for PartnersEnhancing SaaS Performance: A Hands-on Workshop for Partners
Enhancing SaaS Performance: A Hands-on Workshop for Partners
 
The Top Outages of 2023: Analysis and Takeaways
The Top Outages of 2023: Analysis and TakeawaysThe Top Outages of 2023: Analysis and Takeaways
The Top Outages of 2023: Analysis and Takeaways
 
The Top Outages of 2023: Analysis and Takeaways
The Top Outages of 2023: Analysis and TakeawaysThe Top Outages of 2023: Analysis and Takeaways
The Top Outages of 2023: Analysis and Takeaways
 
ThousandEyes Enterprise Digital Workshop - Spanish
ThousandEyes Enterprise Digital Workshop - SpanishThousandEyes Enterprise Digital Workshop - Spanish
ThousandEyes Enterprise Digital Workshop - Spanish
 
ThousandEyes Enterprise Digital Workshop - German
ThousandEyes Enterprise Digital Workshop - GermanThousandEyes Enterprise Digital Workshop - German
ThousandEyes Enterprise Digital Workshop - German
 
ThousandEyes Enterprise Digital Workshop
ThousandEyes Enterprise Digital WorkshopThousandEyes Enterprise Digital Workshop
ThousandEyes Enterprise Digital Workshop
 

Último

Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Último (20)

Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 

Intro to DNS

  • 1.
  • 2. 1 • November 15th 2016 • An overview of the Domain Name System, resources, records, name resolution and name servers. DNS Webinar Series • January 17th 2017 • An in-depth view on how to monitor and alert on DNS availability, response time and record mappings. Intro to DNS Monitoring DNS Records and Servers • December 13th 2016 • Tips and examples covering DNS hijacking and DDoS attacks on DNS infrastructure. DNS Security
  • 3. 2 About ThousandEyes ThousandEyes delivers visibility into every network your organization relies on. Founded by network experts; strong investor backing Relied on for critical operations by leading enterprises Recognized as an innovative new approach 31 Fortune 500 5 top 5 SaaS Companies 4 top 6 US Banks
  • 4. 3 • The Domain Name System (DNS) is a helper system for IP. • DNS is: • A naming hierarchy for the Internet • A directory service to translate (resolve) these names to IP addresses • A protocol to perform name resolution • You can think of DNS as a phone book for the Internet, helping you look up IP addresses for a specific name. The Domain Name System
  • 5. 4 • Domain names provide flexibility and human readability to the Internet Protocol. • Domain names used in URLs and email addresses (e.g. www.google.com) are easier for humans to remember than IP addresses. • In addition, network operators may want to switch IP addresses without having to change the domain name. • And network operators may want to have multiple IP addresses assigned to a specific domain name to, for example, serve content from multiple locations. Why DNS Exists
  • 6. 5 There are many DNS record types that store domain name data. Here are 5 commonly used record types: • A - IPv4 address • AAAA - IPv6 address • MX - Email server • NS - Name server • CNAME – Alias to another domain name A DNS record has a Time-to-Live (TTL) that specifies, in seconds, how long it can be cached by a name server. Once it expires, the name server must query for an updated record. DNS Resources and Records
  • 7. 6 • Clients use DNS to resolve a domain name to an IP address. Name servers store DNS records and respond to domain name queries. • Many clients use a recursive name server located in their network to do work on their behalf. If this domain is unknown to the recursive server, it can start at the root. Each name server will provide the most specific answer it can. The recursive server will iterate through the DNS hierarchy of zones to find an authoritative name server that can answer the query. Name Resolution Client (aka resolver) Recursive server (ISP, company, public DNS) Root server a.root-servers.net TLD server a.gtld-servers.net Authoritative server ns2.google.com
  • 8. 7 • Recursive name servers make recursive queries on behalf of DNS clients. They typically exist within ISPs, enterprise networks and public DNS servers (e.g. Google public DNS 8.8.8.8). • Many recursive servers only respond to queries from within their own network. Some, called open resolvers, will respond to queries from any source. • Most recursive servers also cache DNS records, which are valid for the length of the TTL. Recursive Name Servers Client (aka resolver) Recursive server (ISP, company, public DNS) Root server a.root-servers.net TLD server a.gtld-servers.net Authoritative server ns2.google.com Query: www.google.com
  • 9. 8 • There are 13 root name servers that sit atop the DNS hierarchy and are hard coded into any application that uses DNS. These root name servers maintain a list of the top-level domain servers (.com, .uk, .net, etc.). • The answers provided by root and TLD name servers contain the name servers for the next known subdomain. Root and TLD Name Servers Client (aka resolver) Recursive server (ISP, company, public DNS) Root server a.root-servers.net TLD server a.gtld-servers.net Authoritative server ns2.google.com Query: www.google.com Answer: a.gtld-servers.net Query: www.google.com Answer: ns2.google.com
  • 10. 9 • Authoritative name servers have authority to answer queries from other name servers or from DNS clients. The DNS records in an authoritative name server are maintained by domain administrator. • A set of authoritative name servers are assigned for each zone. These may be maintained by the organization itself, or by an external company (UltraDNS, Akamai, Dyn, etc). Many organizations will split name servers between multiple providers for redundancy. Authoritative Name Servers Recursive server (ISP, company, public DNS) Root server a.root-servers.net TLD server a.gtld-servers.net Authoritative server ns2.google.com Query: www.google.com Answer: 172.217.2.46 Answer: 172.217.2.46
  • 11. 10 Why Monitor DNS Record Misconfiguration Server or Network FailureVendor Availability DNSSEC Expiration Cache PoisoningDDoS Attacks
  • 12. 11 Monitor App & Network Connectivity Anywhere Managed DNS Provider Internet 1 On-Premises DNS Local caching resolvers and self-hosted DNS 2 Hosted DNS Authoritative, TLD and Root Name Servers Access Networks Cloud Agents Enterprise Agents Branch Data Center
  • 13. 12 • ns • @ • +trace • +dnssec • +norec ThousandEyes Approach to DNS Monitoring • Authoritative and caching server network • Routing metrics DIG-like Features And Correlation • Store, save, share, baseline, alert With Analysis Enterprise Vendor
  • 14. 13 See what you’re missing. Watch the webinar: https://www.thousandeyes.com/resources/intro-to-dns-webinar