Monday, November 23, 2020

Stuck between a wall and a hard place with DNS for guest wifi

We have a production system with some webservers. From the internet those websites are only reachable through an Incapsula WAF. Then we also have a test system with some servers that are only available on internal IPs and the names only knows to our local DNS.

Now marketing wants to access both systems from the guest wifi (or a special SSID set up for that purpose) to show things to customers. Now I'm stuck with the DNS problem that I can't use the Incapsula IPs if I use our internal DNS and the public DNS doesn't know our internal test system.

We have Fortigate FWs and they do the DNS for the guest wifi. I could do conditional DNS lookup on the fortigates and only use our internal DNS for test system hostnames. However then we would need to change the Fortogates' DNS to a public one and we don't really want to do that.

Anything I can do besides telling marketing to eat my shorts and bookmark the few IPs of the testsystem?



No comments:

Post a Comment