DNS Question

From: Mario Lobo (Mlobo@ear.com.br)
Date: 04/22/02


From: "Mario Lobo" <Mlobo@ear.com.br>
To: freebsd-security@freebsd.org
Date: Mon, 22 Apr 2002 07:57:08 -0300

Hi;

I have a DNS (named) server running on a FreeBSD 4.4 box firewall.

ipfw allows queries to ports 53 and 1024 from any IP inside the private
network (internal interface) and only certain ISP IPs on the external
interface.

I need to open those ports to any IP on the external interface.

Is there any security concerns I should have if I do this ? The only
services I have running are ssh (restricted to specific IPs) and squid
(local only).

Thanks, -
*** Mario Lobo
*** Dean of Computer Department
*** American School of Recife

 

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: DNS Question
    ... > I have a DNS server running on a FreeBSD 4.4 box firewall. ... > network (internal interface) and only certain ISP IPs on the external ... Personally, I would run the DNS in a jail or chrooted, e.g. ...
    (FreeBSD-Security)
  • Re: [Fwd: gkrellmwireless-2.0.2_7 failed on amd64 7]
    ... Who's responsible for this change - who should I nag to fix the ports? ... It seems that several applications relied on this interface ... any wlan signal monitoring apps for FreeBSD apart from Gnome/KDE applets. ...
    (freebsd-current)
  • Re: Macintosh firewall
    ... It's IPFW the same as the one freeBSD comes with. ... the control panel will only let you open or close ports but you can ... use any other way to interface with it ...
    (Security-Basics)
  • FreeBSD Status Report Second Quarter 2006
    ... April-June 2006 Status Report ... With the release of FreeBSD 5.5 and FreeBSD 6.1, ... consider the "Open Tasks lists" provided with some reports. ... Improving Ports Collection ...
    (freebsd-hackers)
  • FreeBSD Status Report Second Quarter 2006
    ... April-June 2006 Status Report ... With the release of FreeBSD 5.5 and FreeBSD 6.1, ... consider the "Open Tasks lists" provided with some reports. ... Improving Ports Collection ...
    (freebsd-current)