{"id":5410,"date":"2018-07-24T09:45:43","date_gmt":"2018-07-24T14:45:43","guid":{"rendered":"https:\/\/www.poweradmin.com\/blog\/?p=5410"},"modified":"2018-09-13T14:06:25","modified_gmt":"2018-09-13T19:06:25","slug":"dns-in-the-cloud-solid-or-not","status":"publish","type":"post","link":"https:\/\/www.poweradmin.com\/blog\/dns-in-the-cloud-solid-or-not\/","title":{"rendered":"DNS in the Cloud\u2013 Solid or Not?"},"content":{"rendered":"<p><span style=\"font-family: verdana, geneva, sans-serif; color: #000000; font-size: 14px;\"><b>by Des Nnochiri<\/b><\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\"><a href=\"https:\/\/www.poweradmin.com\/blog\/wp-content\/uploads\/2018\/07\/cloud-computing-key-showing-internet-security_z16djvdd.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-5414 size-full\" src=\"https:\/\/www.poweradmin.com\/blog\/wp-content\/uploads\/2018\/07\/cloud-computing-key-showing-internet-security_z16djvdd.jpg\" alt=\"\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.poweradmin.com\/blog\/wp-content\/uploads\/2018\/07\/cloud-computing-key-showing-internet-security_z16djvdd.jpg 300w, https:\/\/www.poweradmin.com\/blog\/wp-content\/uploads\/2018\/07\/cloud-computing-key-showing-internet-security_z16djvdd-150x150.jpg 150w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\"><\/a>The Domain Name System (DNS) catalog maps text-based URLs to their specifically-numbered host systems. As the phone book or Yellow Pages of the internet, DNS governs the speed with which websites and online resources may be located, so the speed and robustness of your DNS service can have a profound impact on your internet performance overall.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-size: 14px;\"><span style=\"font-family: verdana, geneva, sans-serif;\">T<\/span><span style=\"font-family: verdana, geneva, sans-serif;\">his can have an effect not only on the speed at which your staff may gain access to the information and resources they need, but also on the experience of your customers and supply chain partners, at their various touch points with your organization\u2019s internet presence.<\/span><\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">While many enterprises still rely on internal servers and infrastructure for their DNS provision, the option of shifting this function to the cloud is gaining traction. There are <a href=\"https:\/\/www.networkworld.com\/article\/3273891\/hybrid-cloud\/dns-in-the-cloud-why-and-why-not.html\" rel=\"nofollow\" target=\"_blank\">plus and minus points<img class=\"extlink-icon\" src=\"https:\/\/www.poweradmin.com\/blog\/wp-content\/plugins\/external-links-nofollow-open-in-new-tab-favicon\/images\/extlink.png\"><\/a> to this approach, which we shall be considering in this article.<\/span><\/p>\n<p>\u00a0<\/p>\n<h2><span style=\"font-family: verdana, geneva, sans-serif;\">The Cloud DNS Advantage<\/span><\/h2>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">DNS in the cloud is generally considered to be an Infrastructure as a Service (IaaS) solution. And like other cloud-based service offerings, hosted DNS provides a managed, off-site solution which benefits from the geographically dispersed and multi-faceted resources available to the service provider. These resources may typically be much more extensive than those which could be provided by the consumer.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Cloud DNS services are in most cases better able to ensure redundancy and fault tolerance in the infrastructure that they offer. Geographic dispersal of their servers allows for greater scope in DNS resolution between locations, which for the customer provides reduced latency and faster access to websites and online applications.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Cloud providers can improve on the performance possible with in-house DNS servers, by using their resources to ensure advanced traffic routing. The load-balancing capabilities and geographic spread of their servers allows for the deployment of routing policies such as simple failover, latency-based routing, round-robin, geographic DNS and geo-proximity routing.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Costs may be significantly reduced for the enterprise as well, since a cloud DNS deployment relieves subscribers of the burden of infrastructure purchasing, management, and maintenance. Subscription fees may also be significantly less than the equivalent costs of an in-house DNS set-up.<\/span><\/p>\n<h2><span style=\"font-family: verdana, geneva, sans-serif;\">Security Benefits<\/span><\/h2>\n<p><a href=\"https:\/\/www.poweradmin.com\/blog\/wp-content\/uploads\/2018\/07\/cloud-computing-key-means-internet-security_zjst9zvu.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-5417 size-full\" src=\"https:\/\/www.poweradmin.com\/blog\/wp-content\/uploads\/2018\/07\/cloud-computing-key-means-internet-security_zjst9zvu.jpg\" alt=\"\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.poweradmin.com\/blog\/wp-content\/uploads\/2018\/07\/cloud-computing-key-means-internet-security_zjst9zvu.jpg 300w, https:\/\/www.poweradmin.com\/blog\/wp-content\/uploads\/2018\/07\/cloud-computing-key-means-internet-security_zjst9zvu-150x150.jpg 150w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\"><\/a><\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Distributed Denial of Service (DDoS) attacks, where networks are bombarded with information requests, to overload the system, are a common menace for internet-dependent businesses. With their multiple servers and DNS infrastructure, cloud providers are better able than most organizations to provide resistance against this type of assault.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Malicious modification of information passing through DNS servers is another cause of great concern to businesses, as are other <a href=\"http:\/\/searchcloudsecurity.techtarget.com\/tip\/DNS-attacks-Compromising-DNS-in-the-cloud\" rel=\"nofollow\" target=\"_blank\">forms of attack which may compromise DNS<img class=\"extlink-icon\" src=\"https:\/\/www.poweradmin.com\/blog\/wp-content\/plugins\/external-links-nofollow-open-in-new-tab-favicon\/images\/extlink.png\"><\/a> operations, reduce or stop network availability, and negatively affect applications, internal processes, and customer-facing aspects of the business.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Cloud DNS providers that support Domain Name System Security Extensions (DNSSEC), an encryption technology capable of authenticating DNS records and <a href=\"https:\/\/searchcloudsecurity.techtarget.com\/tip\/DNS-in-the-cloud-Building-a-secure-DNS-architecture\" rel=\"nofollow\" target=\"_blank\">guarding against many of the common DNS security issues<img class=\"extlink-icon\" src=\"https:\/\/www.poweradmin.com\/blog\/wp-content\/plugins\/external-links-nofollow-open-in-new-tab-favicon\/images\/extlink.png\"><\/a>, can reduce or eliminate this anxiety for their customers.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">DNSSEC is a relatively new technology, and many organizations aren\u2019t yet familiar with its workings and configuration. A cloud-hosted DNS service can provide the IT expertise necessary for deploying and managing this security system.<\/span><\/p>\n<h2><span style=\"font-family: verdana, geneva, sans-serif;\">Maintenance and Monitoring Capabilities<\/span><\/h2>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Likewise, the \u201cmanaged services\u201d aspect of DNS in the cloud assumes the responsibility for maintaining and monitoring the infrastructure and servers. Under the terms of a typical Service Level Agreement (SLA), the cloud provider takes on the tasks of keeping active and redundant DNS servers patched, secured, scanned, and monitored.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Event reporting, performance information, and operational metrics can also be made available to business consumers for internal auditing and compliance purposes. Most providers will have custom scripts and software-programmable interfaces, for the automatic creation and updating of DNS records. They may also make application programming interfaces (APIs) available to subscribers, enabling businesses to configure dynamic alterations or additions to their own DNS resource records.<\/span><\/p>\n<h2><span style=\"font-family: verdana, geneva, sans-serif;\">The Downside of Cloud DNS<\/span><\/h2>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Of course, it\u2019s not all good news. The classic enterprise objection to cloud-hosted services (\u201cWe\u2019d be entrusting our data\/software\/resources\/infrastructure to a third party!\u201d) holds for DNS in the cloud, as well.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Specifically, relying on an external provider to ensure that your DNS resolution and network availability are always on, can have dire consequences if their infrastructure goes down, or their company goes out of business.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">There may be compensation or punitive damages available for provider outages written into the terms of your SLA, but there\u2019s little guarantee that this will cover the financial losses suffered by your enterprise in the event of a serious cloud DNS disaster.<\/span><\/p>\n<h2><span style=\"font-family: verdana, geneva, sans-serif;\">Proximity and Geolocation Issues<\/span><\/h2>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Having your DNS resolver as close as possible to its DNS client helps guard against latency in your network connections, and this is usually the case, with on-premises DNS deployment. With a cloud service, there\u2019s no guarantee that the DNS resolver the provider makes available will be located nearby.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Problems with geo-location can create issues for international users (clients and staff) if Content Delivery Networks (CDNs) direct connections to a server that\u2019s physically closer to the cloud host\u2019s DNS resolver than to your actual location. This can cause delays and performance issues, including the alteration of expected content due to international or local restrictions.<\/span><\/p>\n<h2><span style=\"font-family: verdana, geneva, sans-serif;\">A Lack of \u201cTightness\u201d<\/span><\/h2>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">DDI \u2013 the integration of DNS, DHCP (Dynamic Host Configuration Protocol, used in automatically providing and assigning IP addresses), and IPAM (IP Address Management) into a unified service \u2013 is easier, if all the resources required for its management reside on a single platform. This is often the case with on-premises DNS but may be harder to achieve with the distributed DNS infrastructure of a cloud service.<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Well-integrated DDI functions make IP address usage highly visible to the enterprise, and facilitate the management of addressing resources. The looseness associated with a cloud deployment can deny businesses the benefit of this integration.<\/span><\/p>\n<h2><span style=\"font-family: verdana, geneva, sans-serif;\">A Lack of Fine-Grained Control<\/span><\/h2>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Complete control of your DNS configuration may not be possible with some cloud providers. Organizations with highly complex environments to manage may not be fully served by the simplified web controls offered by some cloud DNS services.<\/span><\/p>\n<h2><span style=\"font-family: verdana, geneva, sans-serif;\">Choosing a DNS Provider<\/span><\/h2>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">If you\u2019re in the market for a cloud DNS service, you should first identify and prioritize the features that your business will require. Then, assess the available alternatives based on whether:<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">\u00b7 Is the service free, or subscription-based?<\/span><\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">\u00b7 Is there a web interface for comprehensive configuration?<\/span><\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">\u00b7 Does the provider have a redundant and scalable DNS server infrastructure, with high bandwidth dual-protocol connectivity?<\/span><\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">\u00b7 Are anycast addressing and dynamic routing pre-configured to the provider\u2019s name services?<\/span><\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">\u00b7 Do they provide the security features you require, e.g., DDoS protection, anti-spoofing, or packet scrubbing?<\/span><\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">\u00b7 Will they implement DNSSEC for your domain, and configure your DNSSEC resource records?<\/span><\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">\u00b7 Does the service provide APIs and programmable interfaces for automation and in-house configuration?<\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family: verdana, geneva, sans-serif; font-size: 14px;\">Leading names in the DNS cloud market include Akamai, Amazon Route 53, Cloudflare DNS, ClouDNS, DNSMadeEasy, Google Cloud DNS, Infoblox, Microsoft Azure DNS, Oracle, and Verisign Managed DNS.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>by Des Nnochiri \u00a0 The Domain Name System (DNS) catalog maps text-based URLs to their specifically-numbered host systems. As the phone book or Yellow Pages of the internet, DNS governs the speed with which websites and online resources may be located, so the speed and robustness of your DNS service can have a profound impact [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":5478,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17,4,42,6],"tags":[28,27,121,122,123,29],"class_list":["post-5410","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud","category-general-it","category-security","category-tech","tag-cloud","tag-dns","tag-domain-name-system","tag-iaas","tag-infrastructure-as-a-service","tag-security"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/posts\/5410","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/comments?post=5410"}],"version-history":[{"count":5,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/posts\/5410\/revisions"}],"predecessor-version":[{"id":5775,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/posts\/5410\/revisions\/5775"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/media\/5478"}],"wp:attachment":[{"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/media?parent=5410"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/categories?post=5410"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/tags?post=5410"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}