Re: [fw-wiz] (no subject)

From: Barney Wolff (barney@pit.databus.com)
Date: 02/19/03

  • Next message: Rob Payne: "Re: [fw-wiz] DNS and Firewalls"
    From: Barney Wolff <barney@pit.databus.com>
    Date: Wed, 19 Feb 2003 15:38:02 -0500
    

    On Wed, Feb 19, 2003 at 06:50:26AM +0100, Reckhard, Tobias wrote:
    >
    > I don't have much faith in how today's firewalls handle DNS, so I always use
    > proxies and servers that I believe to be secure. However, the DNS standards
    > say that DNS UDP responses must not be larger than 512 bytes, so a firewall
    > is perfectly compliant if it drops those packets.

    This is no longer true; see RFCs 2671 & 3226. A firewall that drops
    UDP over 512 is impeding functionality with no offsetting gain in
    security. Handling fragments is a more interesting case, but certainly
    an unfragmented UDP DNS response should not be dropped simply because
    of its size.

    DNS should be handled by an ALG (eg a caching server) at the firewall,
    to protect vulnerable implementations inside. That precaution is quite
    independent of response size.

    -- 
    Barney Wolff         http://www.databus.com/bwresume.pdf
    I'm available by contract or FT, in the NYC metro area or via the 'Net.
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    


    Relevant Pages

    • Re: Adobe Photoshop
      ... >>server behind your firewall. ... You computer initiates the dns requests, ... > connection for the server to return the response on. ... >>however is when you have slow DNS servers that delay in response. ...
      (comp.security.firewalls)
    • Re: DHCP assinged DNS servers dont work
      ... Although the WinXP firewall is enabled and configured via Group ... The first two DNS servers are AD controllers running ONLY core ... I have 75 WinXP machines on a Win2K3 domain using DHCP for address ...
      (microsoft.public.windows.server.networking)
    • Re: Automatic primary zone to primary zone transfers???
      ... [That is the ICF (firewall) even though ICF and ICS are on the same dialog.] ... They are AD Integrated DNS servers. ...
      (microsoft.public.windows.server.dns)
    • Re: Weird DNS behavior
      ... All my DNS servers are behind a firewall and, ... you have to either fix the firewall to allow DNS to use ... Cisco PIX, block these UDP packets, because they exceed 512 bytes. ...
      (microsoft.public.windows.server.dns)
    • Re: Internet Time Out
      ... the Names Servers for star-kcorp.com are found as below. ... star-kcorp.com nameserver = dns3.name-services.com ... Are all these your DNS servers?? ... Further are you using a third party firewall? ...
      (microsoft.public.windows.server.dns)