Run DNS server or allow DNS requests to traverse security zones?
I recently helped a customer go from a completely flat network into a segmented network. They only have one DNS server which sits on their server network. I'm finding that over half of my sessions are related to DNS queries coming from clients on other networks trying to get to the server network.
Does it make more sense for me to run a DNS server on the firewall and forward DNS queries or should I continue to let DNS traffic traverse the firewall?
I'm running a 300c on 5.0.7 and averaging around 15k sessions during peak usage. In the current setup it often peaks out the CPU but memory stays around 40%.
