Building blocks
Design goal
Avoid overlapping address space, ambiguous DNS ownership, and fragile forwarding paths across enterprise and cloud networks.
Success criteria
- Avoid overlapping address space
- Document ownership of networks and DNS zones
- Create deterministic DNS forwarding paths
- Separate dynamic client addressing from infrastructure addressing
Architecture
Use centrally governed address plans, resilient DNS services, scoped DHCP, and documented forwarding between enterprise and cloud DNS resolvers.
Architecture flow
- IPAM owns address plans
- DHCP allocates approved client ranges
- DNS resolves enterprise zones
- Conditional forwarding connects cloud/private namespaces
Architecture decisions
Plan address space before connectivity
WhyOverlapping CIDR ranges make hybrid routing and service integration much harder to operate.
Trade-offUp-front IP planning reduces future routing conflicts, but reserves address space that may appear underused in the short term.
Make DNS forwarding explicit
WhyDocument which resolver is authoritative for each namespace and where conditional forwarding occurs.
Trade-offDeterministic forwarding improves troubleshooting, but creates resolver dependencies that must be redundant and documented across network boundaries.
Security
Protect the control and data paths deliberately. Restrict administrative access, protect dynamic DNS updates, and audit changes to zones, scopes, and reservations.
Availability
Design for the failure domain that must be survived. Run redundant DNS and DHCP services for networks that require continuous name resolution and address allocation.
Cost drivers
- Managed resolver services
- Appliance/VM compute
- Logging
- Cross-network DNS traffic where metered
Design assumptions
- Enterprise IP ownership can be centrally governed
Implementation plan
- Define one source of truth for address ownership, environment/site hierarchy, subnet allocation, and reserved ranges before connecting networks.
- Design DHCP scopes, exclusions, reservations, relay paths, and failover behavior around the actual client networks that need dynamic addressing.
- Define authoritative DNS zones, ownership, record-registration behavior, and which teams are allowed to change each namespace.
- Create conditional forwarding/resolver paths between enterprise and cloud namespaces with redundant targets and explicit routing dependencies.
- Enable query/IPAM logging where required and test forward/reverse resolution, DHCP allocation, overlap detection, and resolver failure.
Validate the design
- Resolve representative forward and reverse records from each connected namespace.
- Fail one resolver/DNS service and confirm clients continue through the designed redundant path.
- Attempt or detect an overlapping address allocation and confirm IPAM prevents or surfaces it before connectivity is established.
- Request DHCP leases for representative clients and verify reservations, exclusions, options, and relay paths behave as designed.