← Back to context

Comment by Nextgrid

4 years ago

I wouldn't be surprised if their internal infrastructure uses the domain to talk between its services and is now blowing up all over the place too.

Use two networks! Internal NS for example.lan and public NS for example.com

  • You don’t need to use two separate domain names for that. Best practice is to use the external domain internally, and use your internal DNS server to point the records to internal IP addresses. That way you can still get public certs issued to internal services.