Re: Firewall question
From: Chris (never@work)
Date: 03/15/03
- Next message: Lars M. Hansen: "Re: Firewall question"
- Previous message: Wayne McGlinn: "Re: Checkpoint Log analyser!"
- In reply to:(deleted message) Jesper Skriver: "Re: Firewall question"
- Next in thread: Wayne McGlinn: "Re: Firewall question"
- Reply: Wayne McGlinn: "Re: Firewall question"
- Reply:(deleted message) Jesper Skriver: "Re: Firewall question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Chris" <never@work> Date: Sat, 15 Mar 2003 15:03:55 -0000
"Jesper Skriver" <harvest@wheel.dk> wrote in message
news:slrnb76ehs.16vh.harvest@freesbee.wheel.dk...
> On Sat, 15 Mar 2003 14:26:57 -0000, Chris wrote:
>
> > I agree. TCP 53 is only used for zone transfers between DNS servers,
> > not DNS lookups.
>
> Not correct, lookup's will fallback to TCP if the reply cannot fit a
> single UDP packet.
>
> > Besides, the mail server in question will only need to query MX
> > records when sending out mail if not using a smart host. UDP 53 is all
> > it needs.
>
> See above.
>
> --
> Jesper Skriver, CCIE #5456
> FreeBSD committer
When building Firewall-1 firewalls for customers we only ever let UDP 53 out
for hosts that need to resolve DNS and we've never had to let TCP 53 out as
well. In this application I think that UDP 53 will do the job.
Chris.
- Next message: Lars M. Hansen: "Re: Firewall question"
- Previous message: Wayne McGlinn: "Re: Checkpoint Log analyser!"
- In reply to:(deleted message) Jesper Skriver: "Re: Firewall question"
- Next in thread: Wayne McGlinn: "Re: Firewall question"
- Reply: Wayne McGlinn: "Re: Firewall question"
- Reply:(deleted message) Jesper Skriver: "Re: Firewall question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|