Information Systems:Proposal to migrate to externally-hosted DNS

From uniWIKI
Revision as of 10:29, 10 March 2017 by Norwinu (talk | contribs)
Jump to navigation Jump to search

Overview

Maintenance on the Infoblox appliances will soon require (as of March 2017) renewal for another year. At this time, it is appropriate to consider externally-hosted DNS in lieu of continuing with on-site DNS using these appliances.

Advantages/disadvantages of on-site vs. externally-hosted DNS

It is important to note that whether on-site vs. externally-hosted, the basic function of serving DNS records is the same i.e. the differences are in aspects other than core functionality.

On-site

Pros:

  • The biggest pro is the unintended consequence of being a small company and thus, flying under the radar. That means we're arguably less susceptible to DDoS, by simple virtue of us (and our DNS hosting) being too unimportant to hack. Meanwhile, attacks on DNS providers cause massive outages that can make an emphatic point for black-hat hackers. It is not a coincidence that TV shows portraying computer hacking e.g. Mr. Robot focus on DNS-hacking storylines.
  • DNS uptime coupled to Web server uptime (for the most part). Arguably the most important function of our DNS hosting is to enable traffic to Web Orders. If our network is down for any reason, DNS likely would be down too, and vice versa. This is not so much an advantage, but a consequence of neutral bearing.
  • Vanity of having on-site DNS. When you query NS records for unipharm.com (i.e. who does DNS for unipharm.com?), you will get uni3sys.unipharm.com, indicating we likely do our own DNS (although some external DNS providers also let you do this for extra cost). Again, not really an advantage.
  • More "control" over its "physical" operation.


Cons:

  • No failover. More and more DNS providers are offering failover mechanisms with their DNS service, to ensure uptime for companies with multiple paths (WAN connections) to their services.
  • Higher cost of service
  • Vulnerable to DDoS attacks. While less susceptible to such an attack, if someone were to target our DNS servers, we do not have the resources (advanced network monitoring and security) to successfully thwart such an attack. We'd be forced to pull the plug or migrate to our failover WAN line (so basically, running away). If the attack on Dyn required 4 hours of recovery time, a similar attack on our DNS servers would cripple the network here for much longer.
  • High overhead i.e. costs associated with managing the appliance/virtual appliance. The machine physically exists here so it must be managed. This is self-explanatory, and relative to not having a machine here at all, the magnitude of this point should be fairly obvious.
  • High initial cost of software (virtual appliance itself and the licensing).
  • Technical inefficiency of the operation. We serve only a handful of DNS records, and they rarely change. Yet the DNS infrastructure we maintain is meant for
  • Performance. This may not be noticeable, but in terms of sheer performance (i.e. DNS response time, time-to-first-byte etc.), one DNS server cannot compete with the massive CDN (content-delivery networks) and clusters of high-performing servers that an external DNS provider offers.

Externally-hosted DNS

Pros:

  • Cost. DNS providers have drastically come down in price. Just as a ballpark, $4000 for a new Infoblox virtual appliance and $1500 for 3 years of support for a device that at best can be stretched to 5-7 years before best practices necessitate replacement, compared to USD$60 per year for business-level DNS service.
  • Failover service.
  • Redundancy through geographical distribution of DNS servers: any service will have more servers (thousands), and located at different parts of the world
  • Off-load DNS traffic from our network. DNS traffic is not so much a threat to bandwidth, but rather to network security. DNS security

Cons:

  • Per-instance support billing. Given the nature of DNS as functionally basic but critically important, DNS providers invest in their infrastructure and as a result, dedicated support staff ("one number to call") is less of a priority.