RE: Cisco Workaround

From: Naman Latif (naman.latif_at_inamed.com)
Date: 07/23/03

  • Next message: David J. Bianco: "Re: ARP Spoof Question"
    Date: Wed, 23 Jul 2003 09:22:15 -0700
    To: "Alvaro Gordon-Escobar" <alvaroge@molecularstaging.com>, <firewalls@securityfocus.com>, <security-basics@securityfocus.com>
    
    

    No.
    DNS uses UDP (or on some cases TCP). Protocol numbers for UDP and TCP
    are 17 and 6 respectively. You are denying protocols 53,55,77,103 so DNS
    will work as before.

    Regards \\ Naman
    > -----Original Message-----
    > From: Alvaro Gordon-Escobar [mailto:alvaroge@molecularstaging.com]
    > Sent: Wednesday, July 23, 2003 7:15 AM

    > will this access list modification prevent my internal DNS
    > server from updates to it self from my telco's DNS server?
    >
    > access-list 101 deny 53 any any
    > access-list 101 deny 55 any any
    > access-list 101 deny 77 any any
    > access-list 101 deny 103 any any
    > !--- insert any other previously applied ACL entries here
    > !--- you must permit other protocols through to allow normal
    > !--- traffic -- previously defined permit lists will work
    > !--- or you may use the permit ip any any shown here
    > access-list 101 permit ip any any

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: David J. Bianco: "Re: ARP Spoof Question"

    Relevant Pages

    • Re: SMTP delivery failure when NIC DNS server points to router
      ... I learned that the router's DNS server does not listen to TCP queries. ... Configure the SMTPSVC to use UDP for DNS queries. ...
      (microsoft.public.inetserver.iis.smtp_nntp)
    • RE: Help with ipfw rules to allow DNS queries through
      ... If a DNS reply exceeds the maximum size of a udp datagram, it will be sent using TCP so the rule is needed. ... > I have a stand alone server co-located on my employers T1 line. ...
      (FreeBSD-Security)
    • Re: Windows 2003 Help
      ... Reconfigure the DC's as also posted in DNS NG: ... In the private ip range i would not enable the firewall between the DC's. ... 53211 TCP ... 53 TCP and UDP ...
      (microsoft.public.windows.server.general)
    • SMTP Outgoing - Connection Dropped
      ... Searching for Exchange external DNS settings. ... Checking TCP/UDP SOA serial number using DNS server. ... TCP test failed. ... UDP test succeeded. ...
      (microsoft.public.windows.server.sbs)
    • Re: new server 2003 slow login NOT a DNS problem
      ... If i see your DNS server ip's their is a mismatch with your current subnet ... UDP:138 ... TCP:445 ...
      (microsoft.public.windows.server.general)

  • Quantcast