Aug 15, 2017

Possible to use GTMs for public DNS records without allowing internet access to GTMs?

We use GTMs internally for GSLB services - however, we don't use them for general purpose DNS. Instead, we allow our internal DNS servers to recursively resolve the references to GTM-hosted zone records/wide IPs, so that the clients never directly execute DNS requests against the GTMs. (we understand and accept that this limits us to not using latency or client source IP geo for wide IP conditioning).


We would like to employ the same strategy for our public DNS records. However, we don't want to turn recursion on for our public name servers, because of the risk of DOS attacks.


Has anyone successfully configured DNS services to accomplish this goal - having public internet DNS clients only send requests to the standard, non-GTM DNS servers, but have those servers accomplish the same goal as recursively responding, without turning on recursion in general for the DNS server?


