Re: 53 udp/tcp

From: Ric Griffy (alakevue.at@tampabay.rr.com)
Date: 11/28/02


From: "Ric Griffy" <alakevue.at@tampabay.rr.com>
Date: Thu, 28 Nov 2002 16:10:18 GMT

I would also restrict outgoing port 53 to the IP's of your ISP only.
Ric Griffy

"Juergen Nieveler" <juergen.nieveler.nospam@arcor.de> wrote in message
news:Xns92D4A2494B75Cjuergennieveler@nieveler-43544.user.cis.dfn.de...
> "Doug Fox" <dfox168@hotmail.com> wrote:
>
> > The rule (FW-1) allows out-bound (out-going) traffic. Could
> > "external" intruders tunnel their traffic through that port? How is
> > it achieved?
>
> Not external intruders.
>
> But internal users could use port 53 just like any other port to tunnel
> requests through it, thus circumventing the firewall.
>
> As an example, take all those HTTP-Tunneling-systems: They forward
> traffic addressed to a local proxy via Port 80 to another system that
> has a specific proxy running and re-transmits the data to the intended
> systems.
>
> As this rule is for port 53, I'm guessing that you want to give your
> users the ability to use DNS. How about setting up a local DNS server
> that forwards the DNS requests to the Internet (and also caches DNS)?
>
> That way, you only have to allow one server to access the Internet
> directly.
>
>



Relevant Pages

  • Re: how do you setup a wireless connection without using DNS in the NIC?
    ... I CURRENTLY HAVE NODES CONNECTED TO A SWITHC - NETOPIA ROUTER CONNECTED TO ... THE SWITCH AND FROM THE WAN PORT ADTRAN T1 ROUTER. ... PUBLIC CHANGE THEIR NIC TO RECOGONIZE THE DNS IP. ... building) and have them access the Internet via their lap top. ...
    (microsoft.public.windows.server.setup)
  • Re: OWA timeout
    ... Well if it works internally and not externally then it is either port ... dns server have the both the MX and A records? ... > timeout may have occurred due to Internet congestion. ... > Contact website: You may want to contact the website administrator to make ...
    (microsoft.public.windows.server.active_directory)
  • RE: Pubstro rash
    ... > listens on port 53. ... have your own DNS server for resolution of your own ... permits Internet hacker:port x -> your network:port 53 ...
    (Incidents)
  • Re: 53 udp/tcp
    ... > But internal users could use port 53 just like any other port to tunnel ... How about setting up a local DNS server ... > that forwards the DNS requests to the Internet? ...
    (comp.security.firewalls)
  • Re: Event ID: 5504
    ... User Datagram Protocol, Src Port: 1273, Dst Port: domain ... Authority RRs: 0 ... and if its an issue with the Windows DNS ... > assuming (none of us have asked your config yet) that you have all your ...
    (microsoft.public.win2000.dns)