<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#ffffff" text="#000000">
    "ANY". That NS record tells *the*world* (not just your ISP) that
    they can come to your nameserver to resolve names in the zone.<br>
    <br>
    It wouldn't be much a failover strategy if you were relying on your
    ISP's nameservers to somehow "proxy" the queries over to you, when
    they're down. <br>
    <br>
    Open up inbound destination port 53 TCP/UDP (for queries) and
    outbound source port 53 TCP/UDP (for responses). The destination
    port outbound will be the same as the source port inbound, for a
    given DNS transaction, if your firewalls are stateful enough to keep
    track of such things.<br>
    <br>
                                                                       
                                        - Kevin<br>
    <br>
    On 9/18/2011 12:01 PM, babu dheen wrote:
    <blockquote
      cite="mid:1316361662.97636.YahooMailNeo@web137302.mail.in.yahoo.com"
      type="cite">
      <div style="color: rgb(0, 0, 0); background-color: rgb(255, 255,
        255); font-family: times new roman,new york,times,serif;
        font-size: 12pt;">
        <div><span>Hi,</span></div>
        <div><span>  Once i delegated NS record in my ISP name server to
            my company name server for mail.myoffice.com website as
            below. Do i need to allow DNS port from ANY(INTERNET) to my
            DNS server in firewall or i just need to allow DNS traffic
            only from ISP DNS server</span></div>
        <div><span></span> </div>
        <div><span>ISP DNS server configuration</span></div>
        <div><span></span> </div>
        <div><span>mycompany-dns-server-ip   IN<span class="tab">    A
              10.10.10.10</span></span></div>
        <div><span>mail.myoffice.com<span class="tab">    <span
                class="tab">           IN<span class="tab">    NS<span
                    class="tab">    <mycompany dns server ip></span></span></span></span></span></div>
        <div> </div>
        <div> </div>
        <div>Regards</div>
        <div>Papdheen M<br>
        </div>
        <div style="font-family: times new roman,new york,times,serif;
          font-size: 12pt;">
          <div style="font-family: times new roman,new york,times,serif;
            font-size: 12pt;"><font face="Arial" size="2"><b><span
                  style="font-weight: bold;">From:</span></b> Kevin
              Darcy <a class="moz-txt-link-rfc2396E" href="mailto:kcd@chrysler.com"><kcd@chrysler.com></a><br>
              <b><span style="font-weight: bold;">To:</span></b>
              <a class="moz-txt-link-abbreviated" href="mailto:bind-users@lists.isc.org">bind-users@lists.isc.org</a><br>
              <b><span style="font-weight: bold;">Sent:</span></b>
              Sunday, 18 September 2011 5:09 PM<br>
              <b><span style="font-weight: bold;">Subject:</span></b>
              Re: Query regarding NS record<br>
            </font><br>
            <meta content="off" http-equiv="x-dns-prefetch-control">
            <div id="yiv2026477857">
              <title></title>
              Are you talking about recursive clients failing over?<br>
              <br>
              Or other nameservers trying to talk to yours,
              non-recursively?<br>
              <br>
              Recursive clients don't use NS records at all and you need
              to approach the failover problem in a completely different
              way (e.g. relying on the client failing over from one
              resolver IP address to another, or implementing an Anycast
              solution).<br>
              <br>
              If you're talking about nameserver-to-nameserver traffic,
              then just publish multiple NS records for the relevant
              zone(s) and the nameserver-selection algorithm embedded in
              every known iterative-resolver implementation will take
              care of the load-balancing and failover; to summarize,
              faster-responding nameservers will be chosen over
              slower-responding ones.<br>
              <br>
                                                                     
                                                                     
                                                                     
                          - Kevin<br>
              <br>
              On 9/16/2011 11:17 AM, babu dheen wrote:
              <blockquote type="cite">
                <div style="color: rgb(0, 0, 0); font-family: times new
                  roman,new york,times,serif; font-size: 12pt;
                  background-color: rgb(255, 255, 255);">
                  <div>Hi,</div>
                  <div>    Can anyone let me know how i can resolve the
                    below requirement.</div>
                  <div> </div>
                  <div> </div>
                  <div>Requirement:</div>
                  <div> </div>
                  <div>We have two offices. One is main office and
                    another one is remote branch office. Now my company
                    client requirement is that if main office DNS server
                    is not reachable, all DNS query should be sent to
                    branch office DNS server. How this can be acheived
                    using BIND?</div>
                  <div> </div>
                  <div>For example, my company mail website is;
                    mail.mycompany.com which is pointed as below in ISP
                    name server.</div>
                  <div> </div>
                  <div>mail.mycompany.com<span class="yiv2026477857tab">    <span
                        class="yiv2026477857tab">    IN<span
                          class="yiv2026477857tab">    NS<span
                            class="yiv2026477857tab">    ns1.mainoffice.com</span></span></span></span></div>
                  <div><span class="yiv2026477857tab"><span
                        class="yiv2026477857tab"><span
                          class="yiv2026477857tab"><span
                            class="yiv2026477857tab">mail.mycompany.com<span
                              class="yiv2026477857tab">    <span
                                class="yiv2026477857tab">    IN<span
                                  class="yiv2026477857tab">    NS<span
                                    class="yiv2026477857tab">    ns1.branceoffice.com</span></span></span></span></span></span></span></span></div>
                  <div><span class="yiv2026477857tab"><span
                        class="yiv2026477857tab"><span
                          class="yiv2026477857tab"><span
                            class="yiv2026477857tab"><span
                              class="yiv2026477857tab"><span
                                class="yiv2026477857tab"><span
                                  class="yiv2026477857tab"><span
                                    class="yiv2026477857tab"></span></span></span></span></span></span></span></span> </div>
                  <div><span class="yiv2026477857tab"><span
                        class="yiv2026477857tab"><span
                          class="yiv2026477857tab"><span
                            class="yiv2026477857tab"><span
                              class="yiv2026477857tab"><span
                                class="yiv2026477857tab"><span
                                  class="yiv2026477857tab"><span
                                    class="yiv2026477857tab">  Is the
                                    above record is correct or not?</span></span></span></span></span></span></span></span></div>
                  <div><span class="yiv2026477857tab"><span
                        class="yiv2026477857tab"><span
                          class="yiv2026477857tab"><span
                            class="yiv2026477857tab"><span
                              class="yiv2026477857tab"><span
                                class="yiv2026477857tab"><span
                                  class="yiv2026477857tab"><span
                                    class="yiv2026477857tab"></span></span></span></span></span></span></span></span> </div>
                  <div><span class="yiv2026477857tab"><span
                        class="yiv2026477857tab"><span
                          class="yiv2026477857tab"><span
                            class="yiv2026477857tab"><span
                              class="yiv2026477857tab"><span
                                class="yiv2026477857tab"><span
                                  class="yiv2026477857tab"><span
                                    class="yiv2026477857tab"> Please
                                    suggest.</span></span></span></span></span></span></span></span></div>
                  <div><span class="yiv2026477857tab"><span
                        class="yiv2026477857tab"><span
                          class="yiv2026477857tab"><span
                            class="yiv2026477857tab"><span
                              class="yiv2026477857tab"><span
                                class="yiv2026477857tab"><span
                                  class="yiv2026477857tab"><span
                                    class="yiv2026477857tab"></span></span></span></span></span></span></span></span> </div>
                  <div><span class="yiv2026477857tab"><span
                        class="yiv2026477857tab"><span
                          class="yiv2026477857tab"><span
                            class="yiv2026477857tab"><span
                              class="yiv2026477857tab"><span
                                class="yiv2026477857tab"><span
                                  class="yiv2026477857tab"><span
                                    class="yiv2026477857tab">Regards</span></span></span></span></span></span></span></span></div>
                  <div><span class="yiv2026477857tab"><span
                        class="yiv2026477857tab"><span
                          class="yiv2026477857tab"><span
                            class="yiv2026477857tab"><span
                              class="yiv2026477857tab"><span
                                class="yiv2026477857tab"><span
                                  class="yiv2026477857tab"><span
                                    class="yiv2026477857tab">papdheen M</span></span></span></span></span></span></span></span></div>
                  <div><span class="yiv2026477857tab"><span
                        class="yiv2026477857tab"><span
                          class="yiv2026477857tab"><span
                            class="yiv2026477857tab"></span></span></span></span> </div>
                  <div><span class="yiv2026477857tab"><span
                        class="yiv2026477857tab"><span
                          class="yiv2026477857tab"><span
                            class="yiv2026477857tab"></span></span></span></span> </div>
                  <div><span class="yiv2026477857tab"><span
                        class="yiv2026477857tab"><span
                          class="yiv2026477857tab"><span
                            class="yiv2026477857tab">  </span></span></span></span></div>
                  <div><span class="yiv2026477857tab"><span
                        class="yiv2026477857tab"><span
                          class="yiv2026477857tab"><span
                            class="yiv2026477857tab"></span></span></span></span> </div>
                </div>
                <pre><fieldset class="yiv2026477857mimeAttachmentHeader"></fieldset>
_______________________________________________
Please visit <a moz-do-not-send="true" class="yiv2026477857moz-txt-link-freetext" href="https://lists.isc.org/mailman/listinfo/bind-users" rel="nofollow" target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a> to unsubscribe from this list

bind-users mailing list
<a moz-do-not-send="true" class="yiv2026477857moz-txt-link-abbreviated" href="mailto:bind-users@lists.isc.org" rel="nofollow" target="_blank" ymailto="mailto:bind-users@lists.isc.org">bind-users@lists.isc.org</a>
<a moz-do-not-send="true" class="yiv2026477857moz-txt-link-freetext" href="https://lists.isc.org/mailman/listinfo/bind-users" rel="nofollow" target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a></pre>
              </blockquote>
              <br>
            </div>
            <meta content="on" http-equiv="x-dns-prefetch-control">
            <br>
            _______________________________________________<br>
            Please visit <a moz-do-not-send="true"
              href="https://lists.isc.org/mailman/listinfo/bind-users"
              target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a>
            to unsubscribe from this list<br>
            <br>
            bind-users mailing list<br>
            <a moz-do-not-send="true"
              href="mailto:bind-users@lists.isc.org"
              ymailto="mailto:bind-users@lists.isc.org">bind-users@lists.isc.org</a><br>
            <a moz-do-not-send="true"
              href="https://lists.isc.org/mailman/listinfo/bind-users"
              target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a><br>
            <br>
          </div>
        </div>
      </div>
    </blockquote>
    <br>
  </body>
</html>