hello joel,
unfortunately I need the dns-services. I come up with another idea:
we have this equipment:
cablemodem -> zyxel router with nat -> every outside traffic goes to 192.168.0.3, the ip-address of our dns-/file-/mail-server. our domain is hosted outside the network. in the lan I use the same domainname as we have outside hostet by our provider. the mx-record points to the ip-address of the zyxelrouter. everything works fine.
my question is:
if I activate the firewall and configure the port 53 to allow access inside the network and only the ip-adress of the nameserver of our hostingprovider from outside, will our mail-server be accessible from outside?
I think, if somebody send me an email (e.g. [email protected]), his mail-server checks the nameserver of our hostingprovider, find the information, that mail.mydomain.com has the ipaddress x.x.x.x and sends then directly the email to our server. so if this mailserver sends the email, does he need our dns-server to reach the mailserver, or does his mailserver directly connect to our email-server?
or to ask generally: is there a reason, why our lan-dns-server should be reachable from the outside?
many thanks for your help in advance!
yours sincerely
ferdinand
Comments are closed