[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: DNS & IP Addresses (was Re: dich cai gi, khong dich cai gi)



DHBK dung NAT va masquerate la vi khong du IP cho cac may .

Toan bo intranet cua DHQG co gan 2000 may tinh nhung chi co 32 IP registered
tho^i. Ne^n ddo la giai phap.


>    Anh NgoHa & anh CaoTri me^'n,
>
>    Sau dda^y la` nh~ nha^.n xe't trung thu+.c, kho^ng co' y' che^ bai de`
> bi?u, va` ra^'t tho^ng ca?m vo+'i hoa`n ca?nh internet cu?a VN.
>
>    Theo to^i tha^'y co' va`i ddie^?m DNS o+? VN ca^`n gia?i quye^'t:
>
>    1. VN ca^`n ngay class A addresses, kho^ng nha^'t thie^'t ca^`n pha?i
> ddo+.i dde^'n IPv6.

DHBK cung da tham du inet 99 ta.i My~ va` ho. ddo^`ng y' cho mo^.t class B
nhung ma thu tuc de routing ve den DHBK thi XIN mot qua nen thoi.
Hon nua hien tai duong truyen cung qua cham nen chua xin lam gi`

>
>    2. VN ne^n thay ddo^?i ca'ch ddie^`u ha`nh zone & DNS cho ro~ ra`ng va`
> hie^.u nghie^.m. Ca'ch hie^.n tho+`i co' ve? luo^.m thuo^.m.
>
>    Va`i ddie^?m sau dda^y ra^'t ... mo+ ho^` va` nghe kho^ng co' ly' cho
> la('m:
>
>    1. Vi` ly' do gi` APNIC chi? ca^'p cho VN 32 Class-C IP addresses? I't
> nha^'t VN pha?i co' tu+` class B tro+? le^n, chu+' class-C addresses na`o
> chi.u cho no^?i cho ca? mo^.t quo^'c gia\? Ne^'u APNIC cho+i e'p VN, chi?
> cho "nga^`n a^'y" thi` to^i nghi~ co' the^? VN dda~ kho^ng/chu+a "chu+'ng
> minh" ddu+o+.c so^' lu+o+.ng IP addresses ca^`n va`o lu'c la^.p ddo+n?
> Ho+n nu+~a, Class-C addresses thi` thie^'u, chu+' class-A addresses thi`
> co`n ra^'t nhie^`u! Ne^'u tu.i APNIC cho+i the^' thi` tha^.t dde^?u! Va`
> VN ca^`n la`m ddo+n xin la.i mo^.t "block" class A dde^? tu+. tri.\.
>
>    2. To^i kho^ng hie^?u ta.i sao -DHBK "mie^`n con" (sub-domain) la.i o+?
> trong DNS cu?a VN (.vn)? DDa'ng le~ ra -DHBK pha?i o+? trong -DHQG (.edu)
> va` ro^`i www/ftp cu?a -DHBK o+? trong -DHBK DNS (.hcmut) chu+'! DDa^y co'
> pha?i la` policy va` tru+o+`ng ho+.p "kie^?m soa't cha(.t che~" cu?a .vn
> kho^ng? Hay chi? la` thie^'u resources (hosts & DNS) cho ne^n mo+'i pha?i
> ke^'t ho+.p nhie^`u sub-domains va`o trong mo^.t zone?

cac entry cua www.hcmut.edu.vn , va cac truong dai hoc khac chi la mot host
entry thoi khong phai la mot DNS server entry

>
>    3. To^i kho^ng nga.c nhie^n ne^'u -DHBK du`ng NAT & Masquerades trong
> giai ddoa.n pho^i thai, gia?i quye^'t nha^'t tho+`i khi IP addresses co`n
> thie^'u hu.t. Chu+' nhu+ du`ng ca'ch na`y dde^? gia?i quye^'t va^'n dde^`
> security thi` qua' ... tho^ so+!. Co' nhu+~ng ca'ch gia?i quye^'t kha'c
> elegant ho+n (VPN, Firewall, sec-router, sec-gateway).
>
Khong pha?i vi` security dau.
Security da co firewall - packet filltering,...