SlideShare a Scribd company logo
1 of 12
Private DNS Infrastructure support in
Hybrid Azure scenarios
DNS is the phonebook of the
internet and your private
network
Private DNS DNS Private Resolver Public DNS
Azure Private DNS / Private DNS
Zones
Private DNS Records supports custom
domains for the organization & private
endpoint. You link virtual networks to
these zones so records can be read.
Azure DNS Private Resolver
Allowed you to extend your on-
prem DNS infrastructure
into Azure.
Allows you to query records
in private DNS zones from an on-
prem environment and vice versa.
Azure DNS / DNS Zones
Used for Public DNS Records
e.g. We have a public record
for api.org.edu.au pointing to
the public IP of the application
gateway which fronts the APIM
Azure DNS
How to extend your on-prem DNS into Azure
IaaS supported
• Operational Management: Requires OS support
such as patching etc.
PaaS supported
• Fully managed: Built-in high availability, zone redundancy.
• Scalability: High performance per endpoint.
• Cost reduction: Reduce operating costs and run at a fraction of
the price of traditional IaaS solutions.
DNS Private Resolver
DNS Private Resolver Configuration - PaaS
A Virtual Network with dedicated inbound and outbound subnets /28 CIDR range on both.
• 1 or more inbound endpoints are supported (dedicated/visible IP from the subnet)
• 1 or more outbound endpoints are supported
DNS Server Configuration on your Virtual Network (Hub and all spokes)
• For each inbound endpoint you have, you list it as a DNS server in your VNET config
Each outbound endpoint has a DNS forwarding rule set associated
• Multiple rules can exist within 1 rule set i.e. multiple domains can be forwarded on
DNS Forwarding Rule Sets
Rules
The individual rules in a ruleset determine how these DNS names are resolved.
• A domain name
• A target IP address
• A target Port and Protocol (UDP or TCP)
Virtual Network Links
Virtual network links for DNS forwarding rulesets enable resources in other VNets to use forwarding rules when resolving DNS names.
You link virtual networks to these rulesets to ensure they are considered when a query is trying to be evaluated.
For Hub-Spoke Topology (less management)
Central DNS approach only requires links to the VNET which the DNS resolver is deployed into, hence the central DNS approach.
For Non Hub-Spoke Topology e.g. legacy network infrastructure (more management)
Requires more admin of VNETs, forwarding ruleset links and private DNS zones.
DNS forwarding rulesets enable you to specify one or more custom DNS servers to answer
queries for specific DNS namespaces.
Setting the Scene
IP: 10.10.10.2
Scenario 1 - Azure to Azure
Scenario 2 - On-prem to Azure
Scenario 3 - Azure to On-Prem
Thankyou!

More Related Content

Similar to Private DNS Infrastructure Support in Hybrid Scenarios

Pmw2 k3ni 1-2b
Pmw2 k3ni 1-2bPmw2 k3ni 1-2b
Pmw2 k3ni 1-2b
hariclant1
 
Pmw2 k3ni 1-2b
Pmw2 k3ni 1-2bPmw2 k3ni 1-2b
Pmw2 k3ni 1-2b
hariclant1
 

Similar to Private DNS Infrastructure Support in Hybrid Scenarios (20)

Dns Configuration
Dns ConfigurationDns Configuration
Dns Configuration
 
Dns Configuration
Dns ConfigurationDns Configuration
Dns Configuration
 
02 configuring and-troubleshooting-dns
02 configuring and-troubleshooting-dns02 configuring and-troubleshooting-dns
02 configuring and-troubleshooting-dns
 
02 configuring and-troubleshooting-dns
02 configuring and-troubleshooting-dns02 configuring and-troubleshooting-dns
02 configuring and-troubleshooting-dns
 
Pmw2 k3ni 1-2b
Pmw2 k3ni 1-2bPmw2 k3ni 1-2b
Pmw2 k3ni 1-2b
 
Pmw2 k3ni 1-2b
Pmw2 k3ni 1-2bPmw2 k3ni 1-2b
Pmw2 k3ni 1-2b
 
Dns
DnsDns
Dns
 
Dns
DnsDns
Dns
 
DHCP
DHCPDHCP
DHCP
 
DHCP
DHCPDHCP
DHCP
 
DNS Records Explained @ Hackveda
DNS Records Explained @ HackvedaDNS Records Explained @ Hackveda
DNS Records Explained @ Hackveda
 
DNS Records Explained @ Hackveda
DNS Records Explained @ HackvedaDNS Records Explained @ Hackveda
DNS Records Explained @ Hackveda
 
Dns interview
Dns interviewDns interview
Dns interview
 
Dns interview
Dns interviewDns interview
Dns interview
 
Zone in windows server 2012
Zone in windows server 2012Zone in windows server 2012
Zone in windows server 2012
 
Zone in windows server 2012
Zone in windows server 2012Zone in windows server 2012
Zone in windows server 2012
 
Session_2.ppt
Session_2.pptSession_2.ppt
Session_2.ppt
 
Session_2.ppt
Session_2.pptSession_2.ppt
Session_2.ppt
 
Domain Name Server
Domain Name ServerDomain Name Server
Domain Name Server
 
Domain Name Server
Domain Name ServerDomain Name Server
Domain Name Server
 

More from Daniel Toomey

More from Daniel Toomey (20)

Azure Logic Apps & AI - Building Integration & AI Solutions
Azure Logic Apps & AI - Building Integration & AI SolutionsAzure Logic Apps & AI - Building Integration & AI Solutions
Azure Logic Apps & AI - Building Integration & AI Solutions
 
Microsoft Azure News - May 2024 - BAUG'24
Microsoft Azure News - May 2024 - BAUG'24Microsoft Azure News - May 2024 - BAUG'24
Microsoft Azure News - May 2024 - BAUG'24
 
Azure Logic Apps and Copilot.pptx .
Azure Logic Apps and Copilot.pptx      .Azure Logic Apps and Copilot.pptx      .
Azure Logic Apps and Copilot.pptx .
 
Microsoft Azure News - April 2024 .
Microsoft Azure News - April 2024      .Microsoft Azure News - April 2024      .
Microsoft Azure News - April 2024 .
 
Microsoft Azure News - Feb 2024
Microsoft Azure News - Feb 2024Microsoft Azure News - Feb 2024
Microsoft Azure News - Feb 2024
 
Microsoft Azure News - Dec 2023
Microsoft Azure News - Dec 2023Microsoft Azure News - Dec 2023
Microsoft Azure News - Dec 2023
 
Microsoft Azure News - Nov 2023
Microsoft Azure News - Nov 2023Microsoft Azure News - Nov 2023
Microsoft Azure News - Nov 2023
 
Microsoft AzureNews - Oct 2023
Microsoft AzureNews - Oct 2023Microsoft AzureNews - Oct 2023
Microsoft AzureNews - Oct 2023
 
Microsoft Azure New - Sep 2023
Microsoft Azure New - Sep 2023Microsoft Azure New - Sep 2023
Microsoft Azure New - Sep 2023
 
Microsoft Azure News - Aug 2023
Microsoft Azure News - Aug 2023Microsoft Azure News - Aug 2023
Microsoft Azure News - Aug 2023
 
Microsoft Azure News - Jul 2023
Microsoft Azure News - Jul 2023Microsoft Azure News - Jul 2023
Microsoft Azure News - Jul 2023
 
Microsoft Azure News - Jun 2023
Microsoft Azure News - Jun 2023Microsoft Azure News - Jun 2023
Microsoft Azure News - Jun 2023
 
Microsoft Azure News - May 2023
Microsoft Azure News - May 2023Microsoft Azure News - May 2023
Microsoft Azure News - May 2023
 
Microsoft Azure News - Apr 2023
Microsoft Azure News - Apr 2023Microsoft Azure News - Apr 2023
Microsoft Azure News - Apr 2023
 
Microsoft Azure News - Mar 2023
Microsoft Azure News - Mar 2023Microsoft Azure News - Mar 2023
Microsoft Azure News - Mar 2023
 
Microsoft Azure News - Feb 2023
Microsoft Azure News - Feb 2023Microsoft Azure News - Feb 2023
Microsoft Azure News - Feb 2023
 
Microsoft Azure News - Jan 2023
Microsoft Azure News - Jan 2023Microsoft Azure News - Jan 2023
Microsoft Azure News - Jan 2023
 
Microsoft Azure News - Dec 2022
Microsoft Azure News - Dec 2022Microsoft Azure News - Dec 2022
Microsoft Azure News - Dec 2022
 
Microsoft Azure News - Nov 2022
Microsoft Azure News - Nov 2022Microsoft Azure News - Nov 2022
Microsoft Azure News - Nov 2022
 
Microsoft Azure News - Oct 2022
Microsoft Azure News - Oct 2022Microsoft Azure News - Oct 2022
Microsoft Azure News - Oct 2022
 

Recently uploaded

Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
panagenda
 
Structuring Teams and Portfolios for Success
Structuring Teams and Portfolios for SuccessStructuring Teams and Portfolios for Success
Structuring Teams and Portfolios for Success
UXDXConf
 
Breaking Down the Flutterwave Scandal What You Need to Know.pdf
Breaking Down the Flutterwave Scandal What You Need to Know.pdfBreaking Down the Flutterwave Scandal What You Need to Know.pdf
Breaking Down the Flutterwave Scandal What You Need to Know.pdf
UK Journal
 

Recently uploaded (20)

Working together SRE & Platform Engineering
Working together SRE & Platform EngineeringWorking together SRE & Platform Engineering
Working together SRE & Platform Engineering
 
How we scaled to 80K users by doing nothing!.pdf
How we scaled to 80K users by doing nothing!.pdfHow we scaled to 80K users by doing nothing!.pdf
How we scaled to 80K users by doing nothing!.pdf
 
TEST BANK For, Information Technology Project Management 9th Edition Kathy Sc...
TEST BANK For, Information Technology Project Management 9th Edition Kathy Sc...TEST BANK For, Information Technology Project Management 9th Edition Kathy Sc...
TEST BANK For, Information Technology Project Management 9th Edition Kathy Sc...
 
(Explainable) Data-Centric AI: what are you explaininhg, and to whom?
(Explainable) Data-Centric AI: what are you explaininhg, and to whom?(Explainable) Data-Centric AI: what are you explaininhg, and to whom?
(Explainable) Data-Centric AI: what are you explaininhg, and to whom?
 
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdfThe Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
 
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
 
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
 
Event-Driven Architecture Masterclass: Challenges in Stream Processing
Event-Driven Architecture Masterclass: Challenges in Stream ProcessingEvent-Driven Architecture Masterclass: Challenges in Stream Processing
Event-Driven Architecture Masterclass: Challenges in Stream Processing
 
Easier, Faster, and More Powerful – Notes Document Properties Reimagined
Easier, Faster, and More Powerful – Notes Document Properties ReimaginedEasier, Faster, and More Powerful – Notes Document Properties Reimagined
Easier, Faster, and More Powerful – Notes Document Properties Reimagined
 
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
 
Structuring Teams and Portfolios for Success
Structuring Teams and Portfolios for SuccessStructuring Teams and Portfolios for Success
Structuring Teams and Portfolios for Success
 
Intro to Passkeys and the State of Passwordless.pptx
Intro to Passkeys and the State of Passwordless.pptxIntro to Passkeys and the State of Passwordless.pptx
Intro to Passkeys and the State of Passwordless.pptx
 
The Metaverse: Are We There Yet?
The  Metaverse:    Are   We  There  Yet?The  Metaverse:    Are   We  There  Yet?
The Metaverse: Are We There Yet?
 
TopCryptoSupers 12thReport OrionX May2024
TopCryptoSupers 12thReport OrionX May2024TopCryptoSupers 12thReport OrionX May2024
TopCryptoSupers 12thReport OrionX May2024
 
WebRTC and SIP not just audio and video @ OpenSIPS 2024
WebRTC and SIP not just audio and video @ OpenSIPS 2024WebRTC and SIP not just audio and video @ OpenSIPS 2024
WebRTC and SIP not just audio and video @ OpenSIPS 2024
 
Design Guidelines for Passkeys 2024.pptx
Design Guidelines for Passkeys 2024.pptxDesign Guidelines for Passkeys 2024.pptx
Design Guidelines for Passkeys 2024.pptx
 
ADP Passwordless Journey Case Study.pptx
ADP Passwordless Journey Case Study.pptxADP Passwordless Journey Case Study.pptx
ADP Passwordless Journey Case Study.pptx
 
Your enemies use GenAI too - staying ahead of fraud with Neo4j
Your enemies use GenAI too - staying ahead of fraud with Neo4jYour enemies use GenAI too - staying ahead of fraud with Neo4j
Your enemies use GenAI too - staying ahead of fraud with Neo4j
 
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdfSimplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
 
Breaking Down the Flutterwave Scandal What You Need to Know.pdf
Breaking Down the Flutterwave Scandal What You Need to Know.pdfBreaking Down the Flutterwave Scandal What You Need to Know.pdf
Breaking Down the Flutterwave Scandal What You Need to Know.pdf
 

Private DNS Infrastructure Support in Hybrid Scenarios

  • 1. Private DNS Infrastructure support in Hybrid Azure scenarios
  • 2. DNS is the phonebook of the internet and your private network
  • 3. Private DNS DNS Private Resolver Public DNS Azure Private DNS / Private DNS Zones Private DNS Records supports custom domains for the organization & private endpoint. You link virtual networks to these zones so records can be read. Azure DNS Private Resolver Allowed you to extend your on- prem DNS infrastructure into Azure. Allows you to query records in private DNS zones from an on- prem environment and vice versa. Azure DNS / DNS Zones Used for Public DNS Records e.g. We have a public record for api.org.edu.au pointing to the public IP of the application gateway which fronts the APIM Azure DNS
  • 4. How to extend your on-prem DNS into Azure IaaS supported • Operational Management: Requires OS support such as patching etc. PaaS supported • Fully managed: Built-in high availability, zone redundancy. • Scalability: High performance per endpoint. • Cost reduction: Reduce operating costs and run at a fraction of the price of traditional IaaS solutions.
  • 6. DNS Private Resolver Configuration - PaaS A Virtual Network with dedicated inbound and outbound subnets /28 CIDR range on both. • 1 or more inbound endpoints are supported (dedicated/visible IP from the subnet) • 1 or more outbound endpoints are supported DNS Server Configuration on your Virtual Network (Hub and all spokes) • For each inbound endpoint you have, you list it as a DNS server in your VNET config Each outbound endpoint has a DNS forwarding rule set associated • Multiple rules can exist within 1 rule set i.e. multiple domains can be forwarded on
  • 7. DNS Forwarding Rule Sets Rules The individual rules in a ruleset determine how these DNS names are resolved. • A domain name • A target IP address • A target Port and Protocol (UDP or TCP) Virtual Network Links Virtual network links for DNS forwarding rulesets enable resources in other VNets to use forwarding rules when resolving DNS names. You link virtual networks to these rulesets to ensure they are considered when a query is trying to be evaluated. For Hub-Spoke Topology (less management) Central DNS approach only requires links to the VNET which the DNS resolver is deployed into, hence the central DNS approach. For Non Hub-Spoke Topology e.g. legacy network infrastructure (more management) Requires more admin of VNETs, forwarding ruleset links and private DNS zones. DNS forwarding rulesets enable you to specify one or more custom DNS servers to answer queries for specific DNS namespaces.
  • 9. IP: 10.10.10.2 Scenario 1 - Azure to Azure
  • 10. Scenario 2 - On-prem to Azure
  • 11. Scenario 3 - Azure to On-Prem

Editor's Notes

  1. Organizations on-prem network Holds: On prem DNS servers, other on-prem source DBs etc. Hub Virtual Network  Holds: DNS Private Resolver, Express Route, Gateways, Firewalls etc. Also the shared private link zones that many workloads across the enterprise would leverage for private resolution. Spoke Virtual Network Holds: spoke / application workload resources e.g. app services, key vaults with private endpoints and workload specific managed dns zones for both public resolution and private resolution.