Re: DNS Question

From: Adam Kujawski (adamkuj@mccoysworld.com)
Date: 08/13/01


Date: Mon, 13 Aug 2001 14:40:35 -0400 (EDT)
From: Adam Kujawski <adamkuj@mccoysworld.com>
To: massara@bridge.com.br
Subject: Re: DNS Question
Message-ID: <Pine.BSF.4.21.0108131436550.75608-100000@mccoysworld.com>

If you disable recursion, your clients will have delays in resolving
name lookups. The best solutions would be to permit recursion only for
certain IP address ranges.

For bind, something like this should work:

options {
        recursion yes;
        allow-recursion {
                127.0.0.1; // localhost
                10.0.0.0/8; // local LAN
                192.168.0.0/24; // etc...
        };
};

-Kuj

On Fri, 10 Aug 2001 massara@bridge.com.br wrote:

> Dear friends,
>
> I have a little question regarding DNS, can you help me??
>
> Since an intrusion test was made at my network, people are talking about
> recursion in DNS. The IT specialists that did the test told me that my DNS
> do recursive queries and its a vulnerability. Im authoritative for some
> zones and the server resolve names for some clients.
>
> If I disable recursion on my servers, am I going to have any trouble???
>
> Thanks in advance,
> Victor
>
>
>



Relevant Pages

  • Re: parent - child DNS in Active Directory
    ... That's the normal behavior, basically the DNS is trying to solve the name that you asked for in its existing domains because you have the SETTINGS configured that force that behavior, this is due your configurations and DNS will act accordantly. ... answer, want recursion, recursion avail. ... refresh = 900 (15 mins) ...
    (microsoft.public.windows.server.active_directory)
  • Re: DNS Cache corruption?
    ... What happened is dhcp is giving out 10.65.6.60 for the DNS Server. ... I have it as a secondary on the stub zone because that's how we have it set up in incognito. ... answer, recursion avail. ...
    (microsoft.public.windows.server.dns)
  • Re: Need to restrict DNS requests to just 5 per second
    ... your clients' operations very noticeably. ... bogus DNS queries per second which causes the traffic utilization to go ... This name server is not authoritative and allows recursion only ... Since I am very new to both FreeBSD and Bind, ...
    (freebsd-questions)
  • Re: microsoft dns server not resolving external Names
    ... "Do not use recursion" is not checked, ... my DNS is resolving names, but only with forwarders configurated, ... >> It seems that I cannot resolve external DNS Names, ...
    (microsoft.public.windows.server.dns)
  • Re: Recursion doesnt work ;-(
    ... Then Kevin replied below: ... > as to allow DNS recursion if I wanted to use it as a forwarder? ... Here is a part of the query I ran against it. ...
    (microsoft.public.win2000.dns)