Re: DNS zone transfer

From: Ed Schmollinger (
Date: 06/10/02

Date: Mon, 10 Jun 2002 09:02:23 -0500
From: Ed Schmollinger <>
To: David Schwartz <>

On Sun, Jun 09, 2002 at 04:18:38PM -0700, David Schwartz wrote:
> On Sun, 9 Jun 2002 13:28:39 -0300, Maximiliano Perez wrote:
> >They can restrict it via:
> >
> > - Filtering port 53/tcp, try telneting.
> They can't filter port 53/tcp if the are authoritative for any domains.
> Support for TCP queries is not optional.

No, they can't filter port 53/tcp if they expect zone transfers or large
responses to work. Being authoritative is independent of the query
mechanism. RFC compliance requires that TCP support be present, but for
most setups, it can be safely disabled (via FW rules or whatever) for
non-secondaries. The security (conscious|zealots) like to disable TCP
because it's harder to get an interactive shell on a machine if you can
only talk to it through UDP.

Ed Schmollinger -

Relevant Pages

  • Re: TCPIP missing!
    ... see Help and Support Center at ... The Simple TCP/IP Services could not find the TCP Echo port. ... The Simple TCP/IP Services could not find the UDP Echo port. ...
  • Re: HTTP over both TCP and UDP
    ... capabilities for clients/servers that didn't support it. ... And there's a very critical reason why it likely won't -- TCP-like ... protocols don't generally interoperate well with TCP on the Internet ...
  • Complemento v0.5 released
    ... I'm happy to announce a new Major Release of Complemento. ... new userland TCP stack ... support for multistage payloads (for complex and stateful protocol, ... support for IPv6 ...
  • Re: asx wont play (similar issue)
    ... Windows Media Player cannot play the file. ... file type or might not support the codec that was used to compress the file. ... UDP checked (TCP is what's needed here, ... Also it's best not to have anything listed in the RTSP "Proxy" box ...
  • WIZnet Chip W3100as TCP/IP Support
    ... that they are supporting TCP, UDP, IP, ICMP etc. ... But i want the detailed features what they support in TCP/IP. ... Time Exceeded, ICMP Echo Request or Reply, ICMP Address ...