Re: 53 udp/tcp

From: David (davidwnh@adelphia.net)
Date: 11/30/02


From: "David" <davidwnh@adelphia.net>
Date: Sat, 30 Nov 2002 04:35:21 GMT

If a DNS server only needs outbound access, how does it get responses for
your queries?
Sure you don't have to have it "listening" on the internet, but you still
have responses coming back. So now you have an additional server running in
which you have to be sure to configure correctly and keep up to date as the
vulnerabilities are exposed and/or fixed.

And if your wondering about the "actual" risks visit a site like CERT or
ISS. You won't be vulnerable to as many without "listening" on the internet,
however you will be vulnerable to more risks than you would without it.
>
> I'd say the risk of running an internal DNS server is minimal - it
> doesn't have to be accessible from the outside, it only needs
> outbound access, and only to the DNS servers of your ISP.
>



Relevant Pages

  • Re: Bind 8
    ... that isn't listening for responses. ... A client program makes a DNS request to DNS server. ... responses on a different port than it did before. ... and the kernel has to bounce all 315 per second ...
    (freebsd-net)
  • Re: Restrict Dynamic Updates
    ... outlined in the article "HOW TO Configure DNS for Internet Access in ... Windows Server 2003", realizing that that was not the initial intent ... internal DNS server host external public data. ... internal DNS server that hosts your internal AD infrastructure access from ...
    (microsoft.public.windows.server.dns)
  • Re: Multihomed DNS server install problems
    ... Is this DNS server hosting your ... > order, and make absolutely sure that both NICs are ... "Configure a forwarder for efficient Internet resolution. ... "If it is hosting public records, then you would tell it to only listen on ...
    (microsoft.public.win2000.dns)
  • Re: DNS not resolving correctly on VPN
    ... When they log in via VPN, we pass the same DNS server. ... I will work with one of this machines today and post back. ... > the users use the OWA from the Internet side? ...
    (microsoft.public.win2000.dns)
  • Re: Is this a split / shadow situation resolving non routable IPs without DNS authourity.
    ... for the clients who use the DC DNS server pair ... External is abc-company.com DNS server for abc-company.com is in our DMZ as well as that web host. ... (This is the single example, reality is there are multiple externals def-company.com, ghi-company.com) ... This DNS server then uses forewarders to resolve Internet ...
    (microsoft.public.win2000.dns)