Understanding DNS
The great thing about using smartphones today is that when I actually want to
contact somebody over the phone I don't dial phone numbers anymore I just go
through my contact list find the person I want to talk to and give me a quick rate.
In fact contactless have become so common on smartphones today that if I were to
lose my contact list I would have a lot of trouble because I don't remember
anybody's cell phone numbers anymore and that could be a big issue.
OK I've got a couple memorized but for the most part I'd be in big trouble.
You see we're so used to using contactless for phones we forget that I'm not
actually calling Mike Meyers mobile.
I'm actually calling a telephone number.
So for us the whole idea of telephone numbers becomes obvious skated because it
disappears into the haze because of contactless.
Now the exact same thing takes place in the computer world.
Now let's say I've got two computers in this case it'll be a web browser and this
will be a web server.
This web browser wants to talk to this web server and the only thing associated
with this web server is an IP address.
So I could go into my little web browser and type in HTTP://
And then this guy's IP address and web page all pull up.
But that's a terrible way to do things because as human beings we're not really
good at memorizing telephone numbers.
I mean IP addresses.
So what we want to do instead is come up with a contactless system for every server
on the Internet.
Now keep in mind the example I'm using right now is a web server but this would
work equally well for an FTP server or S-sh server or a mail server or a world of
tank server it really doesn't matter if you have a server there's an IP address
associated with it.
And as human beings we're terrible at memorizing this.
So we need some kind of contact list.
Well the contact list that I recommend to you is called the domain name system or
DNS DNS is only one thing.
It has all been zillions of computers all over the world whose only job is to your
ready resolve IP addresses based off of fully qualified domain names a fully
qualified domain name.
We've seen them all for example w w w dot totalsem COM or FTP Microsoft dot com or
system dot FBI dot gov.
I mean there's zillions of these computers out there and the DNS is job is to take
these fully qualified domain names and then find out what the IP address for these
individual devices are and then hand it to your computer so it can then work.
Now before I want to get into exactly how DNS works let's take a moment and
understand the structure of fully qualified domain names.
So let's start with one that's near and dear to me.
W w w dot total Sem dot com.
So this is the web server for my company.
Now if we take a look at this and starting on your right my left you're going to
see that there is a dot com There are basically a number of fully qualified top
level domain names.
And you've seen these names like dot com dot edu dot gov.
All of these have to be established if you want your computer to be part of the big
Internet DNS system.
So that's your top level domain.
Now if we go all the way to your left you're going to have the individual host
names.
So for example in this example I have w w w w w w is the name of one individual
computer within the total sim dot com domain.
That's my web server.
And the reason we use W W W is really it's a matter of convention.
People are used to going into their web browsers and typing w w w something when
they want to get to a web server.
I could just as easily call it timmy totalsem . com but I'm going to have a lot of
trouble when people go up to their web browsers.
They're not going to type in timeo I told them noncom they're expecting.
W w w.
So there's no magic to the word w w w It's just good etiquette.
Now this is maybe for web browsers but we do other things for example if I had an
FTP server we by convention use HTTP [Link].
Because people are expecting that for TCP servers.
If this was a mail server people would be expecting probably [Link]
because when people are configuring their web clients they're expecting to type in
something like that.
So the name of the host can be anything there's lot of flexibility here but we do
have conventions that are nothing more than etiquettes for a lot of the more common
applications.
So we got the hostname and we got the top level domain.
Let's talk about this guy in the middle or secondary domain.
Now underneath your top level domains are millions and I mean millions of these
secondary domains and there's all kinds of flexibility in here for example when you
look at this entire fully qualified domain name you'll see it has three pieces the
host the secondary and the top level domain.
There's nothing wrong with that but keep in mind you can have a lot more dots if I
wanted to for example I could have something like w w w dot Houston Texas DOT total
said dot com so you could have.
I believe it's like a 127 individual names but the total length of a fully
qualified domain name cannot be more than 256 characters so you can have a lot of
flexibility in here.
However keeping it simple for right now for the most part is specially for things
that are exposed to the Internet.
You're going to have these three pieces the host the secondary and then the top
level domain.
OK now understanding that we could actually begin to resolve ourselves on the
Internet.
Let's take a look down here now.
What I have here is a web browser over here and a web server over here.
Now the IP address for this web server is 68 one 931 45.
Now if I want my web browser to be able to see this web server I need to get that
IP address to my web browser so that he can open up that web page now to do that we
use DNS.
Now the secret to DNS are the DNS servers.
So first of all I'm going to put a DNS server over here.
Now this DNS server is what we call an authoritative server for the Dell dot com
domain.
Now there are a bunch of listings inside this DNS server and here's one of them.
So w w w dot Del . com is this IP address.
So if we can get something to query this DNS server it has the information we need
and it's ready to give it to us.
Now your computer itself never directly queries a DNS server.
Instead what we do is we have our own DNS server.
So keep in mind the DNS servers do two things they respond to DNS queries and they
create DNS queries and one DNS server can often do both.
But in this case I'm separating the functions So first of all this DNS server.
It might be a DNS server that's in your network.
If you're connecting to an ISP like with a cable modem This is probably controlled
by your Internet service provider.
I don't care where this DNS server is physically.
The important thing is is built into your computer right here.
Our DNS server settings and if you type IP config slash all on this computer you'll
see it's DNS settings.
These settings are provided to your computer.
You can type them in statically.
You can get them through DHCP However you get them.
I guarantee you that your computer has some association with this DNS server
anyway.
So when your computer wants to know the IP address for a particular location what
it's going to do is it sends out a query over to its DNS server and it asks the
question What is the IP address for w w w dot Delcam.
So the first thing your DNS server is going to do is put you on hold so you get the
one of these one moment pleases and a lot of times you can actually see this if you
look at the bottom of a web browser for example you'll see it says things like
waiting for w w w that Delcam.
That's because you're actually waiting for this DNS resolution process to take
place.
So your computer has built into it the DNS settings for your local DNS server
however your DNS server has built into it what are called the root hince the root.
Hence I haven't even gotten them all written down here.
There's a bunch of them and they're built into most DNS servers that are designed
to resolve stuff.
And there are a numbers like 13 different IP addresses that are pretty much never
change.
And these are what are called your root DNS servers your root DNS servers are all
over the world and depending on how your DNS servers setup it will either randomly
or round robin or whatever.
Pick one of these and it will go to one of these IP addresses to what are these
root servers.
Now I actually identify the root servers as just a little dot.
So I put it in quotation marks there so you can actually see the dot and the root
servers job is not to get you to W to dot com but instead what it's going to do is
it's going to respond back and say I can get you to the closest dot com server.
So then we have many many hundreds of all these different type of DNS servers.
Now these DNS servers their job is to be the main DNS servers for anything.
Associate with dot or daddy or dot dot mil or dot org or whatever it might be.
And then your DNS server once he has this information.
He then goes to the com servers and he says OK what's the IP address for Delcam
now.
Because we're talking to the [Link] server.
His job is to know anybody with the last name dot com and he responds back with OK
here it is right here and he sends it over to your DNS server.
So now your DNS server has the IP address for this guy right here so he can then go
over to this guy and say what's the IP address for W.W. that Delcam and he has the
answer and he'll go ahead and respond back to your DNS server with that
information.
Your DNS server and turn will hand that to your computer.
Now the cool part is once your computer has that IP address of course he can go
ahead and talk to that DNS server now and he's going to do that.
But more than that happens for example stored in your computer is a DNS cache.
He will keep that IP address and know that it's associated with [Link] for
a while in case you might eat it again.
Also pretty much any DNS server also caches that.
So if we were to bring another computer in line and that computer wanted to talk to
[Link]
we wouldn't have to go through all this DNS resolution simply because he would be
handling it right there to make sure that this recursive process can take place.
Our main job more than anything else is making sure our individual computers have
DNS server addresses that they can get to and that's a big issue.
DNS servers go up and down all the time.
So one of the fun things we can do with our individual computers is that we can set
up really really popular DNS server names.
One of the most famous is the Google DNS server 8. 8 8 8 8.
It is a super powerful DNS server and it works for just about anybody and you can
type that into your individual computer.
And it's often faster than your own ISP DNS server or anything else.
Keep in mind that this is very cool but if you have your own in-house DNS server
and you try to replace it with a Google when your DNS server might be helping you
resolve for local computers within your network.
And that would be what we call a bad thing.
DNS resolves FQDNs to IP addresses
[Link] is an example of a FQDN
.com and .edu are examples of top-level domains (TLDs)
FQDN = Fully Qualified Domain Name
Applying DNS
So if you want to do DNS you're going to have to start with a DNS server and that's
what I've got right here.
Now to be fair a DNS server is software and right now the entire Internet pretty
much runs on two very famous DNS softwares.
The freeware bind that comes with all UNIX and Unix like systems and also the DNS
server that comes built in with Microsoft Windows Server.
Between those two versions of DNS that's probably 98 percent of all the DNS servers
that are out there.
There's hundreds more but these are the two big ones.
But whatever the case is the actual setup what you have to do to get a DNS server
running is pretty much the same.
So with that understanding let's get a game plan of what we're going to set up and
then we can actually go ahead do that.
So the first thing we're going to have to do if we have a DNS server is where we
have to have a domain.
So I'm going to make up a domain right now I'm going to call it class classroom not
local.
Now this is a very interesting domain because it's not dot com or dot edu or dot uk
and those types of things.
What we're looking at is a domain name that is not really for the Internet.
I'm going to be setting up this DNS server not to set up Web servers or anything
like that but just to allow all the computers in my office to be able to talk to
each other.
So I'm going to give all these computers different names.
You can call this one student and believe it or not call this student on call this
one student too.
And these computers aren't what they might be connect to the Internet so they get
to Google.
But these guys are just if they want to transfer files or something like that.
So in this particular case we're using what's known as an interior DNS server so
this DNS server can use these weird domain names because he doesn't have to
register it with the Internet and we use local.
That's kind of a convention it's a nicety we could type in cheez whiz if we wanted
to there but we tend to use the word dot local to show that it is an internal
domain.
It's not for being used out on the Internet.
Now you need to think about this for a minute because this tends to confuse people
a little bit because I go oh wait a minute Mike I want to be able to get to WWE I
google that come while he can remember that this DNS server he can go ahead and
talk up through the hierarchy of DNS and get to resolving all the Internet names.
But he also is going to be ready for the term the authoritative DNS server for this
domain right here to get this to happen.
We need to start up a DNS server and we're going to have to add a number of
particular types of records.
We add records into what are known as Look-Up zones.
The primary type of zone we have is called a forward lookup zone and so we're going
to set up a forward look of zone for classroom not local.
In fact already got that set up for you and then we're going to start adding
records for all the different types of computers that are within the actual domain.
There's a few more things to do but I think it might be more fun if we head over to
the computer.
Let's actually try this for ourselves.
So for this demonstration I'm going to be using Windows Server 2016.
Keep in mind that I like this one because it's graphical and pretty but we can use
any domain name server to do the exact same thing.
So let's dive into Windows 2068.
Here's the DNS manager that's built into Windows 2016.
And you take a look right here you'll see that I have created Here's my forward
look up zones.
This is part of the reason I like Windows it makes a nice little hierarchy it's
easier for us to understand what's going on.
So I've created a forward look of zone called classroom not local.
Now if you look in here ignore all this Microsoft Google got up here.
What I'm interested in is right here these are four records that we've already
placed into this particular forward lookup zone.
First of all is what we call the start of authority or the way the start of
authority is the DNS server who is the primary DNS server for the zone.
So if I wanted to I could have three or four DNS servers all for classroom local
and if one of them went down if people could get to another DNS server.
However with DNS there's always one big cheese.
And in this particular case this server that I'm running right now because he's the
only one is the start of authorities so if you look right here you'll see where it
says s.a.a second are name servers.
You see this an it's right here.
Remember I said we can have more than one domain name server.
And in this particular case every name server that is part of classroom local would
be listed here.
In this case there's only one.
So and he's the same as the SLA which makes sense.
So one way and one N.S. from here there's a bunch of different types of records
that we can put into a forward look at zone.
So let's just go ahead and start running through some of the more important ones.
Probably the most important of all is the A record that is your standard.
This is one person on this forum look up zone.
So what I want to do is add student 1.
So I'm going to add a record
and I'll make up an IP address.
181 a 56 not 200.
And good student to our in here.
OK so I've added to host records to my domain.
Now two questions come up.
A lot of times when people see this.
Number one they go Well Mike what if I'm using DHC you've just manually typed in IP
addresses.
What if they change because a DHCP.
And the answer there is that DHCP can be programmed to work with DNS and as a
matter of fact if I had these two computers simply join the domain these records
would have automatically been added.
So what I'm doing is I'm statically adding these.
I would do stuff like this for example if I've got a server or something like that
I'd go ahead and statically enter these and then that way I've got an A record now
a record is only for IPV4 for but a quadruple a record is for IPV 6 so this time
I'm going to go in and I'm going to pretend there's a student 3.
Now this time I'm not going to type in an IPV4 address.
I'm actually going to type in an IP D6 address the very short one but it will get
the idea.
And watch what happens now.
Now you see we have what's known as a quadruple A and that's only for IPV 6 so a
record for IPV for quadruplet for IPV 6.
One of the things we run into a lot is sometimes you're going to try to access a
server like it's a web server and everybody types in W W W when we type in a web
server right.
Well you don't have to.
For example I could easily do my total Semb I could do Fred Scott total CENTCOM we
can do any kind of we want but there's only one IP address.
So if we wanted to we could put separate records in.
Probably not the best way to do it.
What we do instead is we would use the concept called canonical name.
What I'm going to do in this particular example is that student 1 I'm going to make
a canonical name which will still direct toward student 1.
Let me show you how this works.
So what we'll do is add a canonical name See name or alias.
And I'm just going to call it Fred.
And we're just going to point it to Student 1 that classroom local.
There we go.
So all I've done here is if somebody gets on the network and they're looking for
Fred they'll be pointed straight towards.
Student 1.
This is a common thing you'll see done and a lot of offices where Bob's machine you
know it's got its own standard name all the time but you know while Bob's there we
call it Bob's classroom not local kind of thing.
Can I to claims are extremely common and we use them all the time.
OK.
Now the next one I want to talk about is probably one of the most important things
we do with DNS and that is a mail exchange or MX record.
All of our tepee mail servers that are out there exchanging mail use DNS and they
get their own special host record called The MX record so usually we have a
dedicated server and usually call it mail very creative name there.
Now if I wanted to I could have it redirect or I'll just type in mail dot classroom
dot local
and what I've done here is I've now created a mail exchanger.
This is how when your mail is being delivered when you upload a piece of mail your
mail servers use the DNS system to get the mail delivered to the right person.
Now this can be a bit of a challenge because it's really easy to spoof mail
servers.
So one of the tricks that we do when it comes to helping get the spam down a little
bit is we create something called a reverse lookup zone a reverse lookup zone
doesn't go from qualified domain name to IP address.
It says If I have an IP address give me a domain name.
It's a very easy way for if I get a request to send on 7000 pieces of mail I might
want to go back say you know what.
Let me double check the IP address.
So a reverse lookup zone does exactly the opposite of a forward lookup zone.
Now it's got a bit of a strange nomenclature so watch this.
So I have created a reverse lookup zone for classroom not local.
First thing I want you to notice is look at that name right there do you see it.
It's actually the network ID backwards with this very specific in Dot ADR dot ARPA
because that's the way these guys set this up.
Now what they can do is that in essence we've got the network ID right here to help
us look stuff up so let's create a pointer record for that mail server
and we'll say that mail servers 2 0 to
and you can see I've now created a pointer record for my mail server reverse look
up zones are not supercritical for most things.
One place they are pretty much required is if you're using mail servers.
I've seen a lot of little in-house networks where they don't even bother with the
reverse lookup zone because they don't need it.
The moment they drop in a mail server and they won't actually send mail around they
put in that reverse lookup zone.
So remember a reverse lookup zone will resolve an IP address to a fault called the
fully qualified domain name whereas a regular for the zone you start with a fully
qualified domain name and a handle and IP address.
All right.
So from here now we got just a couple of more specialized types of host you're
going to run into.
First one I want to talk about is called a server record.
Here we.
This one is so unique I have to actually dig a little bit.
All right.
So this service location or RV record.
There are times when I have certain types of services I'm trying to find a server
that does something.
Now if we wanted to like mail the next records they get their own dedicated host
type.
But there are thousands of different services out there.
So the idea is look instead of making a unique type for every possible service
that's out there we'll make this as our record.
And then you plug in whatever service you want.
These are very very popular with voice over IP systems and a few other situations
that are rare but not so exclusively rare that we shouldn't talk about them for the
network plus.
So let's just go through one example so here I'm going to create a pointer you can
see it's got some defaults in there but I don't trust these.
So I'm going to do one called Cyp which is a popular protocol for voice over IP.
And then I could just I could type it anything I want in here.
I'm just going to type Cyp now priority and wait.
These values don't really mean anything by themselves.
It depends on the service and how the service wants to use these.
For example if you've got a lot of incoming calls and you've got four sip servers
for your voice over IP you can set these two values for how you want the servers to
be prioritized in order.
So usually if I only got one I'll do 10 and 10 and sip is 5 0 6 0 and then I type
in the name of the server providing this service.
In this case I would call it a sip
and you can see I've now created an S R V record.
Like I said as our records are pretty rare you're going to have a specific type of
service that requires them and voice over IP is really really common for that type
of situation.
All right.
So the last one I want to talk about is called a text record text records are kind
of interesting.
Text records have been around for ever.
So what I can do here is I could just type in pretty much anything I want.
Text records for decades were how I was setting up a DNS server.
I would throw in a text record so that Janet.
The Tech who's coming in after me I could say Hey Janet listen all of these records
from 10 to 40 need to be deleted on the 15th.
So it was just a way for us to talk to each other.
However text records have suddenly got a lot more important in the anti-spam world.
There are two types of text records I want to talk about.
There's DKIM and SPF.
Now before I show it to you.
Let's have a little bit of fun.
Me setting up an in-house DNS server that's great for just a little windows network
or something like that.
But what if I have web servers up there that are actually on the Internet.
In that case we tend to move towards what I call an external DNS server and
external DNS servers a DNS server that is registered on to the Internet.
It is trusted by other DNS servers and it allows us to register domains we can
configure those domains we can do anything we want to them.
So in this particular case I'm going to minimize this and I'm going to open up my
web browser and I'm going to let you take a little peek.
At one of my external DNS server providers called name cheap name cheap is famous
for providing great inexpensive and subcase is absolutely free DNS services.
The reason I'm bringing this one up in particular is because here are some examples
of text records that cover both SPF and DKIM.
So if you take a look here this is a text record for my total [Link].
And if you look in here you'll see has an SPF what it has in here more than
anything else.
You'll notice there's an IP address.
You see that what the SPF record does is simply says look except any e-mail that
comes from this IP address if it comes from any place else.
Forget about it.
So that's actually a very handy way so just total seminars folks can go ahead and
use that e-mail server to send out e-mail.
The other one or DKIM which is down here DKIM is actually a key it's a it's a
certificate and this certificate allows us to be able to authenticate any
individual person trying to use the e-mail as a legitimate user.
So here they can do passwords and that type of stuff.
So textfiles have gone a long way from being regular little host records where we
typed in Hey Janet and are now absolutely critical in the world of anti-spam.
You would be hard pressed to find a place where you could set up an e-mail server
anymore where you didn't include both an SPF and DKIM record.
OK.
Now this is a bunch of different records that we've now seen for DNS.
I can't stress enough how important it is for the exam that you're very comfortable
with.
Each one of these record types really the only thing you need to be looking at at
this point in the game is what are they for.
Mainly definitional stuff.
I will also tell you that you should take a chance and get on name cheat and open
yourself up an account and play with it a little bit.
I'm not I'm not a paid sponsor for names.
I'm just telling you as a web site an opportunity to have a place to play and
discover how DNS works.
It's an absolutely great tool.
CNAME record creation makes an alias name, or "Known Name", often created for user
interfacing
A reverse lookup zone will resolve an IP address, to an FQDN, and are used by mail
servers
TXT records, DKML, and SPF are used to identify e-mail users and reduce spam