Upcoming Events

Executive conference

Cloud Connect March 16-18

Comprehensive thought leadership for executives, IT professionals and developers. Topics include: the ROI, cost and economics of on-demand computing; Migration strategies to move from on-premise to cloud-based IT; Vertical cloud specialization, tailoring features and architectures to specific applications, industries, and customer ecosystems

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up
Network + Systems Infrastructure
R E V I E W  
Do It Yourself DNS

  April 3, 2003
  By Joe Hernick and Dean Ellerton


TOC Issue TOC
Printer Print full article
Printer Print this page
Printer Download as PDF
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author
 
  In this article
arrow
Introduction
arrow
BlueCat Networks Adonis
arrow
ApplianSys DNSBox300
arrow
Infoblox DNS One
arrow
Executive Summary | How We Tested | Related Links
arrow
Report Card

Before any old-school hecklers start up, let's get the obvious question out of the way: "Why do I need an appliance to manage DNS when I run my own Domain Name Service for free on an old Linux box (with judicious use of duct tape and/or chewing gum)?"

To find the answer, we invited players in the appliance biz to participate in our first-ever DNS appliance comparison. We kept our selection criteria narrow and did not include any software-only vendors for this review. Products needed to be self-contained hardware-software devices marketed as appliances. Three vendors stepped up to the challenge: ApplianSys, BlueCat Networks and Infoblox.

These vendors tout their products' tight security, fast setup, low maintenance and ease of use. They assert that these boxes are less expensive than conventional server-based DNS in total cost over the long haul. To see if real-world performance equals marketing hype, we installed each appliance on our 600-node production network and lived with it in our Real-World Labs® to see how it met the demands of our internal users and external customers.


We graded each product on ease of setup, overall usability, error-checking capabilities and security features. The results: BlueCat's Adonis won our Editor's Choice award by a whisker. Its superior security and overall usability put it on top, though ApplianSys' DNSBox300 was hot on its heels.

Dishing Up DNS

Managing and maintaining DNS for any size shop can be a challenge. While small companies rely on their ISPs to provide DNS, most companies rely on internal resources running some variant of Unix or Microsoft. Let's face it: If your DNS goes down, you lose touch with the outside world, customers included.

Acknowledging the importance of healthy DNS configurations, the conventional approach requires someone with high-level administrative skills and understanding of your network's topology, so highly compensated individuals wind up devoting a large portion of their time to designing, setting up, maintaining and troubleshooting DNS. The approach works, but the consequence is that DNS often ends up being a large, hidden expense in the IT budget.

So here's our answer to the question of why you need a DNS appliance: All three of the products we tested help manage those hidden expenses by greatly reducing the effort required on the setup, care and feeding side of the equation, freeing up those big-dollar folks to focus on higher-level issues. The goal of these appliances is to make DNS easier to live with. And after extensive testing, we believe that, if your budget allows, these boxes are a worthwhile investment.

All three products can scale and support large installations via additional appliances, up to the DNS limit of 13 name servers per zone. BlueCat and Infoblox offer high-availability (HA) installations; more money will get you additional boxes and better theoretical uptime. We played with the HA setup from Infoblox and liked what we saw. (Without having equipment on hand from BlueCat, we couldn't provide a comparison, and ApplianSys' HA solution is in development. HA on primary DNS is not a high priority, as most shops are running multiple secondary servers.)

Big hosting companies like UltraDNS have reason to be nervous. Although it may take a highly technical person to design a DNS architecture for a global company, these products mean big talent is no longer required to maintain DNS.

Each of our contestants lets an administrator control the appliance (reboot, shut down, hardware and software status, autoupdate of OS and security patches) via remote client software. Standard DNS configuration (time to live and refresh) modifications also are implemented from the client interfaces. All are DHCP- and Dynamic DNS-compatible, and Infobox's DNS One and ApplianSys' DNSBox300 can function as DHCP servers. Although we couldn't test Microsoft Active Directory compatibility in our Macintosh OS and Linux shop, each vendor offers extensive documentation for integrating with a Microsoft environment and can provide customer references for successful implementation in Windows environments.



DNS Appliance Features

click to enlarge

Of course, if you're not using Active Directory in a disparate environment, setting up these appliances is simple. Once configured properly, all the units performed perfectly as primary DNS boxes both in our production environment and under test load. We experienced no outages or interruption of service with any of them. From a user's standpoint, our appliance testing was uneventful. To simulate heavy query volumes, we used the queryperf tool from ISC (available with BIND 9.2 sources, in the contrib folder) to pound the heck out of all three contenders. We ran our tests off a Red Hat Linux client and never stressed CPU or I/O loads above 40 percent. We couldn't quite generate the numbers promised by the vendors (Adonis claims 8,400 queries per second, or 725 million theoretical queries per day, for example), but we could consistently get between 2,000 and 6,000 queries per second on all three appliances using queryperf, for a simulated 172 million to 517 million queries per day.

Each product hosts DNS from a streamlined, hardened OS environment where any services or devices not used to provide name resolution have been stripped from the kernel. (For more on hardened Linux setups, see "Hardened Linux Puts Hackers EnGarde".) Compared with our network's Red Hat Linux box running a GUI tool like QuickDNS 4.x from Men&Mice, life is more convenient with any of these boxes and their autoupdate capabilities. Although we continue to be satisfied with the features and performance of QuickDNS, keeping up with fixes and security patches for the OS platform it rides on can be a bear. Each appliance provides secure DNS functionality in an easy-to-manage box that keeps itself up to date.

Infoblox DNS One provides solid client-to-appliance communication via SSL, and ApplianSys DNSBox300 offers solid primary-to-secondary communication via TSIG (transfer signature). BlueCat Adonis does both. And thanks to blocked ports and hardened Linux setups, all three products offer much better security than BIND on a Unix or Windows Server right out of the box.


start top Introduction BlueCat Networks Adonis 

Best of the Web

Data deduplication: Declawing the clones

Data deduplication is emerging as a critically important new arrow in the storage administrator's quiver to answer hard questions about the increasing problem in storage growth costs.

Quick Read

Compression, Encryption, Deduplication, and Replication: Strange Bedfellows

One of the great ironies of storage technology is the inverse relationship between efficiency and security: Adding performance or reducing storage requirements almost always results in reducing the confidentiality, integrity, or availability of a system.

Quick Read

WAN Optimization Whitelists and Blacklists

Optimization is a fantastic way of saving money and creating really happy customers at the same time, but it doesn't work flawlessly for all applications.

Quick Read

WAN Optimization as a Managed Service: It's Not About the Cost

This insight examines how organizations outsourcing their WAN optimization initiatives to a third-party go about achieving their goals for application performance, reducing operational costs, and streamlining enterprise infrastructure.

Quick Read

  Sponsored Links

Premium Content

Next Generation Data Center, Delivered, November 17th
NWC


Salary

Video