- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-24-2024 11:35 AM
Hi, I have a firewall rule on my Palo Alto to NAT a public IP to a private IP on the DMZ. The external users who don’t work for my company can hit the public IP by DNS name, get onto the website, and view the content etc. This is all working fine. A few times per year I must take the internal DMZ server offline for patching and it could be off for a few hours. Is it possible for me to re-direct the external users still trying to access the DNS name over to an external website while the server is unreachable. I have got a webpage built in Azure to say the server is down for maintenance and can they try later. I was wondering could I do this via DNS proxy or would I be better trying to do this with an external Load balancer.
02-26-2024 06:19 AM
In the DNS proxy you can change or redirect DNS records, but I would not be inclined to expose this to the internet.
You could simply change the DNS A record temporarily to point to a landing page while you work on the server, and then switch the A record back to the correct IP after you're done
if you currently have a TTL of 24 hours, you could change it to 5 minutes the day before the maintenance. 15 minutes before you can update the A record, and then after you're done change the record and set the TTL back to 24 hours.
02-26-2024 06:19 AM
In the DNS proxy you can change or redirect DNS records, but I would not be inclined to expose this to the internet.
You could simply change the DNS A record temporarily to point to a landing page while you work on the server, and then switch the A record back to the correct IP after you're done
if you currently have a TTL of 24 hours, you could change it to 5 minutes the day before the maintenance. 15 minutes before you can update the A record, and then after you're done change the record and set the TTL back to 24 hours.
02-26-2024 02:02 PM
Thanks for the advice - I'll give that a go
03-12-2024 12:53 AM
Thanks for answering, you made my day.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!