Re: [Full-Disclosure] Fw: [NTBUGTRAQ] Win 2003 DNS requests makes replies over 512 byte PIX limit

Valdis.Kletnieks_at_vt.edu
Date: 05/08/03

  • Next message: hggdh: "Re: [Full-Disclosure] Fw: [NTBUGTRAQ] Win 2003 DNS requests makes replies over 512 byte PIX limit"
    To: Mathias Gerber <mathias@intergga.ch>
    Date: Thu, 08 May 2003 17:13:17 -0400
    

    On Thu, 08 May 2003 22:36:16 +0200, Mathias Gerber <mathias@intergga.ch> said:

    > AFAIK the DNS uses TCP for larger replys.

    Back when the maximum usable MTU in the Arpanet was 584, the DNS protocol
    basically said "Send the query as UDP, if reply is over 512 bytes long
    server sends back 'too big', and retry the query as TCP".

    RFC2671 specifies an extension mechanism for DNS (EDNS0), and even if you
    don't use any other extensions provides a convenient way of saying "Use UDP
    if the packet is under 1280 (or 4K, or whatever you specify)". This allows
    the (hopeful) savings of a 3 packet handshake to set up a TCP session and
    another several packets at FIN time.

    However, just as with older firewalls that break RFC3168 ECN (explicit
    congestion notification) because they don't like the use of previously
    "reserved" bits in the TCP SYN packet, some gear doesn't like seeing the
    RFC2671-format DNS queries and drop them on the floor...

    -- 
    				Valdis Kletnieks
    				Computer Systems Senior Engineer
    				Virginia Tech
    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: hggdh: "Re: [Full-Disclosure] Fw: [NTBUGTRAQ] Win 2003 DNS requests makes replies over 512 byte PIX limit"

    Relevant Pages

    • Re: Windows 2003 DNS "stops respond to name queries"
      ... I have re-enabled EDNS0 support and our Network engineer has set the UDP ... packet size to 1300. ... > and DNS will have to make a TCP query to get a good answer. ...
      (microsoft.public.windows.server.dns)
    • Re: Event ID 5504 - Windows 2003 DNS
      ... Use a packet sniffer to see what is in these rejected packets. ... I have seen a case where a machine was sending a query for localhost to DNS ...
      (microsoft.public.windows.server.dns)
    • Re: Nslookup fails for external lookups
      ... > packet filter for DNS on the ISA Server itself. ... > the forwarder on my DNS server that seems to timeout? ... UDP is used ...
      (microsoft.public.win2000.dns)
    • Re: Strange DNS packets
      ... Yes I query several DNSRBL but incoming mail is handled by another SMTP ... The packet in provided log are destined to the outgoing SMTP server. ... >> DNS packet directed to the IP address of our mail server. ...
      (comp.os.linux.security)
    • Re: NETDIAG problem - SPN queries
      ... Ethernet adapter Local Area Connection: ... Connection-specific DNS Suffix. ... There is no primary WINS server defined for this adapter. ... Description: RSVP UDP Service Provider ...
      (microsoft.public.win2000.dns)