Re: Pubstro rash

From: Jeff Kell (jeff-kell_at_utc.edu)
Date: 03/18/05

  • Next message: David Gillett: "RE: Pubstro rash"
    Date: Thu, 17 Mar 2005 19:07:25 -0500
    To: alexandre.skyrme@ciphersec.com.br
    
    

    Alexandre Skyrme wrote:
    > Greetings David,
    >
    > Just a thought about your third comment...
    >
    > As far as I'm concerned DNS just uses 53/TCP to do zone transfers. In case
    > your workstations are on a different network than your DNS servers it should
    > probably be safe to block incoming TCP connections to that network on such
    > port.
    >
    > Tipically zone transfers would only be used by secondary servers to update
    > their own zones from its primary server.

    RFC1035 allows 512 bytes for a DNS response (53) but they may now be
    longer, according to RFC2671 and others. If the DNS query fails or is
    "truncated", the query may be repeated over TCP.

    So, 53/tcp is NOT just for zone transfers.

    Jeff


  • Next message: David Gillett: "RE: Pubstro rash"

    Relevant Pages

    • Re: ad and dns setup
      ... MCSE, MVP Directory Services ... _msdcs, forward zone, reverse lookup zone. ... To fully rebuild DNS: ... changes immediately to all servers, this helps to speedup the process. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Replication issues
      ... I wanted to say Zone Transfers not Zone Forwarding. ... on 2 servers out of 4 DNS servers. ... DNS and 2003 DNS and how to set up Conditional Forwarding. ...
      (microsoft.public.windows.server.active_directory)
    • Re: ad and dns setup
      ... "Jorge Silva" wrote: ... domain It gave me 2 errors, no dns servers have dns records for this dc ... error no logon servers.. ... Make sure that the _msdcs zone exists and the scope is set ...
      (microsoft.public.windows.server.active_directory)
    • Re: Global catalog server died before completing replication to new GC server
      ... What about the DNS zones,are all machines listed there? ... Install DNS role and create a forward lookup zone for your complete ... Then make sure all servers are listed in the zones, ... cause Group Policy problems. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Very Critical issue
      ... the clients are configured to go to local Domain Controller for DNS query. ... created secondary zone for b.com in the root server of a.com and vise versa. ... As we are migrating all the users first, the file and other servers are ... "Jorge Silva" wrote: ...
      (microsoft.public.windows.server.active_directory)

  • Quantcast