Information Systems:Migration to externally-hosted DNS service

From uniWIKI
Jump to navigation Jump to search
This page will either remain a project page (in which case it should be marked to be archived), or will become a meta page for DNS configuration. 

Overview

Project date: Mar. 2017

It has been decided that DNS hosting will be migrated from on-site hosting using Infoblox appliances to third-party DNS hosting providers. This configuration will be tried for a year, after which the solution will be reassessed.

DNS Configuration

Providers

There will be two hosting providers:

It is important to note that service with Dyn.com is purely secondary DNS, and thus records cannot be managed there. Rather, Dyn servers will pull from DNS Made Easy servers through AXFR (an automated, background mechanism requiring configuration at both providers). Any changes made to DNS Made Easy servers will eventually be mirrored onto Dyn servers through periodic NOTIFY syncs, after which those records will begin to be hosted by Dyn servers.

Other details:

  • The plan with DNS Made Easy to which we are subscribed is Business Membership, allowing for 25 domains, 3 failover records, and 10 million queries per month (for all domains).
  • Secondary service is only enabled for unipharm.com and medicinecentre.com. Though we serve other domains, they are not as important as to justify a second level of redundancy through Dyn (the service cost is per domain).

Domains

The following are domains for which uniPHARM is authoritative:

  • unipharm.com
  • medicinecentre.com
  • umccharity.ca

(I guess that's actually it. Wow I thought there were more. -norwizzle (talk))

Technical notes

  • Setup of DNS Made Easy was simply through copying records on the Infoblox. A reassessment of the current records is recommended (e.g. orders.unipharm.com as a CNAME for bart.unipharm.com - why? -norwizzle)
  • Configuration TTL time is currently 1800 seconds (1 hour for all A records).
  • Failover records will not be added until multipath or active redundancy for the WAN is enabled.