Wikiposts
Search

Notices
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Dynamic DNS

Thread Tools
 
Search this Thread
 
Old 17th October 2009 | 14:47
  #1 (permalink)  
Thread Starter
Per Ardua ad Astraeus
 
Joined: Mar 2000
Posts: 18,575
Likes: 4
From: UK
Dynamic DNS

I have been asked (and done) to set up DDNS on my router to allow temporary access to a restricted server for FTP. I have never done this before, and I am uncertain exactly what this means now for my general 'security' via my router? Anybody got it in simple language please? I am using DynDns.com.
BOAC is offline  
Reply
Old 17th October 2009 | 16:05
  #2 (permalink)  
 
Joined: Aug 2002
Posts: 3,663
Likes: 0
From: Earth
BOAC,

First I must confess my practical experience of Dynamic DNS is limited due to more frequent use of static IP and normal DNS. My understanding of it is that there is a DDNS client which keeps the Dynamic DNS service updated with your router/whatever's current IP address.

If that is the case, then the inherent security risks are as follows :

(1) Security vulnerability in the internet exposed DDNS client service leading to a launch point for attacks.

(2) DNS on its own is only there to resolve a name to an IP. Therefore you need to review your general L3 security stance accordingly (filter rules etc.) No specific things need to be checked for DNS in your scenario.
mixture is offline  
Reply
Old 17th October 2009 | 16:11
  #3 (permalink)  
Administrator
 
Joined: Mar 2001
Aviation Qualifications: PPL
Posts: 8,121
Likes: 686
From: Twickenham, home of rugby
BOAC,

As I understand it, you are using DDNS because your IP address may change, being dynamically assigned by your ISP.

DDNS allows your router to update the DDNS service if your IP address changes, so that the DNS name resolution always points to the correct IP address.

Regarding general security - well, you are no less secure than if you had a fixed IP address and used a static DNS.

You presumably have port-forwarding enabled for at least HTTP and FTP so you need to ensure that the server(s) accessible in this way are properly hardened.

If your router / firewall has the ability to create a DMZ for this purpose (hosting publicly-accessible servers), that would be ideal - thus separating the inside network from the publicly-accessible server(s).

SD
Saab Dastard is offline  
Reply
Old 17th October 2009 | 16:42
  #4 (permalink)  
Thread Starter
Per Ardua ad Astraeus
 
Joined: Mar 2000
Posts: 18,575
Likes: 4
From: UK
Great replies, guys - thanks. I'll wade through 'DMZs', port-forwarding etc which are black arts to me. Sounds, though, as if I should be ok - I'm happy with the concept of dyndns.com. and static IPs and yes- my ISP, as usual, allocates floating. I understand that the server I am to access needs to have a fixed IP for me to allow me in. It was the 'big picture' security angle I was unsure of.
BOAC is offline  
Reply
Old 17th October 2009 | 17:12
  #5 (permalink)  
15 Anniversary
 
Joined: Jan 2008
Posts: 1,133
Likes: 0
From: Bracknell, Berks, UK
If I knew how to attach a file to this forum i'd attach a dummy's* guide to networking and the internet in Powerpoint I wrote a few years ago to try and train our call takers. It might help, it might not.



(*no offense implied - just a brand name)
Mike-Bracknell is offline  
Reply
Old 17th October 2009 | 17:31
  #6 (permalink)  
 
Joined: Aug 2002
Posts: 3,663
Likes: 0
From: Earth
Mike,

Stick it on Google dogs or somewhere and give us the link !
mixture is offline  
Reply
Old 17th October 2009 | 17:55
  #7 (permalink)  
 
Joined: Apr 2009
Posts: 349
Likes: 0
From: UK.
Mike,

Upload it to www.rapidshare.com and they can download the file as a free user.
Aerouk is offline  
Reply
Old 17th October 2009 | 19:51
  #8 (permalink)  
15 Anniversary
 
Joined: Jan 2008
Posts: 1,133
Likes: 0
From: Bracknell, Berks, UK
Right, it's not complete, it might contain a few technical inaccuracies for the sake of getting the point across, and it wasn't originally designed for this audience (or to answer 100% of the asked question), but in the interests of teaching others here you go:

RapidShare: 1-CLICK Web hosting - Easy Filehosting
Mike-Bracknell is offline  
Reply
Old 19th October 2009 | 18:49
  #9 (permalink)  
 
Joined: Aug 2000
Posts: 436
Likes: 0
From: Patterson, NY
BOAC,

The servers you need to access, ftp?, do indeed require a static IP address.
Since you are using DDNS then that is not an issue. Simply access the server via dns name, as set up in ddns, and you're good to go. Just make sure you configure the proper security at the ftp server. (I'm familiar with this using Linux and Unix but I"m not so sure about Windows.)
rgbrock1 is offline  
Reply

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.