Re: Pubstro rash

From: Jeff Kell (jeff-kell_at_utc.edu)
Date: 03/18/05

  • Next message: David Gillett: "RE: Pubstro rash"
    Date: Thu, 17 Mar 2005 19:07:25 -0500
    To: alexandre.skyrme@ciphersec.com.br
    
    

    Alexandre Skyrme wrote:
    > Greetings David,
    >
    > Just a thought about your third comment...
    >
    > As far as I'm concerned DNS just uses 53/TCP to do zone transfers. In case
    > your workstations are on a different network than your DNS servers it should
    > probably be safe to block incoming TCP connections to that network on such
    > port.
    >
    > Tipically zone transfers would only be used by secondary servers to update
    > their own zones from its primary server.

    RFC1035 allows 512 bytes for a DNS response (53) but they may now be
    longer, according to RFC2671 and others. If the DNS query fails or is
    "truncated", the query may be repeated over TCP.

    So, 53/tcp is NOT just for zone transfers.

    Jeff


  • Next message: David Gillett: "RE: Pubstro rash"

    Relevant Pages

    • Re: ad and dns setup
      ... MCSE, MVP Directory Services ... _msdcs, forward zone, reverse lookup zone. ... To fully rebuild DNS: ... changes immediately to all servers, this helps to speedup the process. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Replication issues
      ... I wanted to say Zone Transfers not Zone Forwarding. ... on 2 servers out of 4 DNS servers. ... DNS and 2003 DNS and how to set up Conditional Forwarding. ...
      (microsoft.public.windows.server.active_directory)
    • Re: ad and dns setup
      ... "Jorge Silva" wrote: ... domain It gave me 2 errors, no dns servers have dns records for this dc ... error no logon servers.. ... Make sure that the _msdcs zone exists and the scope is set ...
      (microsoft.public.windows.server.active_directory)
    • Re: Setting up DNS; Internet and Intranet questions
      ... have a DSL connection to my firewall/gateway, ... DNS on this mess: The firewall gate way as the master DNS server runs ... The external zone file ... There are two external slave DNS servers. ...
      (Fedora)
    • Re: Trust Relationship Between 2 Domains
      ... All servers except 1 server appeared in the DNS zone of Domain B in Domain ... ACTIVE DIRECTORY FOREST" However in Domain B the same zone's replication ...
      (microsoft.public.windows.server.migration)