Re: DNS server behind a firewall

muxaul_at_lenta.ru
Date: 12/17/04


Date: 17 Dec 2004 07:16:54 -0800

Thanks a lot for the replies!

Typical records in syslog look this way (udp, 53<->53):

kernel: IN=eth0 OUT=eth1 SRC=194.67.81.64 DST=MY_SERVER LEN=72
TOS=0x00 PREC=0x00 TTL=61 ID=2665 PROTO=UDP SPT=53 DPT=53 LEN=52

or this way (tcp):

kernel: IN=eth0 OUT=eth1 SRC=194.67.160.3 DST=MY_SERVER LEN=44
TOS=0x00 PREC=0x00 TTL=59 ID=48041 DF PROTO=TCP SPT=58162 DPT=53
WINDOW=65535 RES=0x00 SYN URGP=0

The rules I described in the first posting permit
these types of connections to a few trusted DNS servers only.
Thus my question can be put this way: is it necessary to ACCEPT
such connections from all possible hosts/DNS servers in the world
or does it suffice to ACCEPT them from a couple of trusted
upper level DNS servers? Actually, once I have called to the
maintainers of a DNS server that was trying to establish TCP connects
with our server and asked them _why_. They did _not_ give me a
definite answer. Still the majority of connection attempts are
of type udp, port 53<->53.

Regards,
Mikhail



Relevant Pages

  • Re: As my customer says it is an odd problem - is it DST, DNS or what? (long)
    ... Some places will refuse email if they can not resolve the machine's ... to change to the Bellsouth DNS servers on their windows system ... using Windows ftp. ... connections if they can not resolve the name/IP combination from ...
    (comp.unix.sco.misc)
  • Firewall service
    ... Lately I had to make some changes in TCP/IP configuration, ... actually only changing the DNS servers address for ... connections on my SBS server. ... Firewall service really have to STOP? ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: thousands of dns.exe UDP connections, what to do?
    ... synattack etc options on and behind it a two DNS servers on Windows 2003 ... uncountable number of DNS UDP connections. ... fyi, I maintain a web server, since Windows 2000 went RTM. ...
    (microsoft.public.windows.server.dns)
  • Re: Multiple internet connections routing.
    ... > such that if one of the internet connections is down, ... - If you don't want load balancing, but just fail-over, then you ... balancing and fail-over in firmware. ... register their addresses as your primary and secondary DNS servers ...
    (comp.os.linux.networking)
  • Re: thousands of dns.exe UDP connections, what to do?
    ... synattack etc options on and behind it a two DNS servers on Windows 2003 ... according to tcpview.exe (from sysinternals) there are an ... uncountable number of DNS UDP connections. ...
    (microsoft.public.windows.server.dns)

Quantcast