All language subtitles for 2. DNS Explained Part 2

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal) Download
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

Now on this Windows computer I'm going to change the DNS server to the Cisco Rhoda

so go to the Ethernet settings rather than using Google as the DNS server and CloudFlare.

I'm only going to specify my local reporter as the DNS server now in this example.

I've configured the right to accept a DNS queries and answer them.

And if it doesn't know the answer to forward it to Google this is once again a Cisco broader.

But to your home right it probably does something very very similar.

So if I type show run piping collude which basically allows me to look for a command and search for

DNS you can see that I've enabled IP DNS server so the writer will act like a DNS server show IP right

shows us that it has a default or brought to a router physically in my local network that say another

Cisco rider that actually physically connects me out onto the Internet.

This device can ping Google dot com.

So if I type show run pipe include name typically I would have IP Name Server something like this but

it actually got to that because the outside interface.

In other words the interface connecting this device to the Internet is using DHEA P so through DHEA

P It learnt the default gateway it also learned to the DNS server information.

So once again it could paying David Bumble dot com as an example.

Now the P.C. won't be able to ping right of one dot whom dot com as an example because the broader isn't

configured with that information on the Cisco router if I try and ping rather one dot home dot com that's

not going to work because it doesn't know about that domain.

Notice it's actually trying to get to the Internet right.

To try and find out what did that domain is.

But if I type IP host and specify a hostname like Rod or one home dot com and then specify an IP address

of let's say 10 dot wonder wonder to fly for the local writer this writer will be able to ping itself

it's done a name resolution locally and the P.C. will also be able to ping that domain I'm gonna flush

the DNS cache so it doesn't have any cached entries locally and then ingenious 3 all run a y short capture

here and what we'll filter for is DNS so basically we'll see a DNS request from the P.C. going to the

right and the broader replying if it does a DNS request so ping are one whom dot com that works in why

a shark we can see the DNS request from another random or ephemeral port going to Port 53 but the DNS

server is 10 1 1 2 5 4 which is the local router it's asking for the IP address of this domain name

and the rowdies replying back saying the IP address of that domain name is 10 1 1 2 5 4 so standard

query for an A record because this is IP version 4 but in this case the query went to the broader now

the road is going to forward on DNS queries that it doesn't know the answer to and we can prove that

by running a y shock capture between the broader and the Internet.

So on this link.

So we're seeing a whole bunch of traffic because that is bridge to my physical network.

But once again what I'll do here is filter for DNS can see some other DNS queries are really taking

place.

On the windows P.C. I'll ping David Bumble dot com once again.

You don't have to use ping you could use an as lookup.

So let me show you that as well.

But notice it did get resolved and it looks like it didn't get forwarded

so let's do an honest look up for a different domain.

Let's say Cisco dot com resolution is this IP address so notice.

There we go.

We've done an NSA lookup notice in this case.

It's a DNS query for both the IP version for address.

So we've got a query for the a record Cisco dot com and then we've also got a query for the IP version

6 IP address.

So in this case the reply came back saying this is the IP address of Cisco IP version 4 and this is

the IP version 6 address and we can see that here.

IP version 6 an IP version 4 in our y shock capture notice that the source IP addresses 1 9 2 1 6 8

1 67 which is actually the road show IP interface brief shows us that that is the IP address of the

router so the router is querying another device for the IP address information because it doesn't know

it locally.

So that's the whole idea with DNS.

If the local DNS server doesn't know the answer it forwards that query to a more authoritative DNS server.

And in this case we're getting both the IP version for IP address as well as the IP version 6 IP address

because I used n s lookup.

Now you need to make sure that the DNS server that you querying is giving you good information.

As an example on this broader I could create a hostname for Cisco dot com and simply pointed to another

IP address.

Let's say the local router on the P.C. I'll flush the DNS cache so flush DNS and then I'll ping Cisco

dot com.

Notice the IP address resolved is 10 1 1 2 5 4.

It's not to the actual IP address of Cisco

so if your DNS entries are manipulated or you connecting to a false DNS server you could end up going

to the incorrect server.

You may think you're going to Cisco dot com or another domain but actually you're being redirected somewhere

else.

So hackers will often target the DNS servers have rogue DNS servers which allow them to push your traffic

where they want to.

Again fortunately because of certificates preloaded on browsers today you may be warned if you go to

the wrong server typically you're not going to use your Cisco writer as a DNS server.

You might use it for DNS requests onto a DNS server on the Internet but you wouldn't want to configure

your local broader as the DNS server.

You may in some cases but typically not what you typically want to use is a linux server to be the DNS

server.

So in this example I'm going to show you how to setup a DNS server on a boon to computer.

Now this is a boon to desktop.

Typically you'd run this on a server rather than a desktop.

But the same principle applies.

So I have config shows us the IP address of the server.

Can we ping Google dot com.

Yes we can.

So we getting a resolution of that domain now to set up this boon to P.C. as a DNS server.

I need to disable system D resolved because there's a conflict on Port 53.

You cannot have two services listening on Port 53.

I want to set up DNS mosque.

So I want to disable this process so that DNS mosque can listen on that port number

so I'm going to disable system D result and then I'm going to stop it.

I'll put all these commands below this video if you want to access this yourself and see the commands.

Next thing I'm going to do is edit I'm just going to use nano for that to keep it simple resolve dot

com.

Name Service set to this at the moment.

I'm gonna set the name server to Google

and then I'm going to do sudo apt update to update references.

It might be a bit slow here because I'm going through the genius 3 network going through Cisco devices

like this in Janus 3 is very slow so speed the video up if necessary

OK so the references have been updated.

So what I'm going to do is install DNS mosque

and that's now been installed.

Now my Mac is going crazy.

There seems to be an issue with VMware Fusion and a Mac where the use starts acting like mad.

So I'm sorry if there's a lot of background noise but hopefully you can hear what I'm saying now to

edit DNS mask it's not that difficult.

I'm going to edit it see Dennis mosque conf now quite a few options that you can change here but I'm

just going to change some of the basics.

Set the port to 53 that is the default

for housekeeping and to be a better net citizen.

I'm going to uncommon domain needed and bogus prove.

So we'll never forward plain domain names onto the Internet and non readable address space and then

essentially all I need to do is uncommon at this because I don't want to use Etsy resolve I'm going

to put domain names directly here.

So what I could do is simply add domain names like all one dot home dot com and the IP address and whatever

other domain names I want to enter.

So let's say my broader whom dot com same IP address and then all I need to do is save that file and

then restart the service.

So sudo sys CTO restart DNS mosque

I can look at the status if I want to

can see that this lightweight DHEA P and caching DNS server is running.

So now on my windows P.C. to prove the point let's configure the DNS server to do your boon to P.C.

so I'm gonna set the DNS server here to 200 which is my boon to P.C. click Okay so let's flush the DNS

DNS that's been flushed.

Do that again.

So can I ping R one dot home dot com.

Yes I can because that's been resolved by the ubuntu server.

That was quite a long video but hopefully you've learned something.

I've shown you how to capture DNS queries and responses using Y shock.

I showed you the source and destination port numbers.

I showed you how you can configure a Cisco router as a DNS server and how to configure and a boon to

P.S. as the DNS server.

And then we tested the queries and made sure that it worked properly.

I'm David Bumble and I want to wish you all the very best.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.