关于AWS入站端点解析器DNS查询方式的技术问询
问题
Can you send a DNS query to an AWS inbound endpoint resolver asking to lookup a record in a private zone for which it has a resolver rule (e.g. by using a standard DNS client such as nslookup / resolve-dnsname); or do these handle resolutions in a different way (e.g. so you can only query them from specific solutions which support some alternate DNS protocol) meaning you have to query via (for example) an AD Domain Controller with a conditional forwarder.
上下文
We have a Route53 Inbound Endpoint Resolver configured in our AWS Transit Gateway account, with transmission protocol set as Do53.
This resolver has a resolver rule to cover requests to our awscloud.private domain; with each of our AWS accounts having their own <myAccountFriendlyName>.awscloud.private (e.g. production.awscloud.private) private zones.
Our ("on prem" / Azure hosted) Active Directory DNS is configured with a Conditional Forwarder for the awscloud.private zone, with the forwarder pointing to the IP addresses of the Route53 Inbound Endpoint.
解答
完全可以用标准DNS客户端(比如nslookup或者PowerShell的Resolve-DnsName)直接向AWS Route53入站解析器端点发送DNS查询,不需要依赖AD域控这类中间服务,除非你自身架构有特殊需求。
原因很直白:你已经将入站端点的传输协议配置为Do53(标准DNS协议),这意味着它完全兼容通用的DNS查询流程。只要你的客户端能通过网络连通到该入站端点的IP地址,就可以直接指定它作为DNS服务器来查询awscloud.private相关的私有域记录。
给你举两个实际操作的例子:
- 使用
nslookup命令:nslookup production.awscloud.private <入站端点IP地址> - 使用PowerShell的
Resolve-DnsName命令:Resolve-DnsName production.awscloud.private -Server <入站端点IP地址>
至于你在AD DNS里配置的条件转发器,它只是一种架构层面的DNS路由优化方案——目的是让内网默认使用AD DNS的机器,能自动把awscloud.private域的查询请求转发到Route53入站端点,这样客户端无需手动指定特殊DNS服务器就能完成查询。但这绝非唯一的方式,直接用标准客户端对接入站端点是完全被支持的。
备注:内容来源于stack exchange,提问作者JohnLBevan

