Great Circle Associates Firewalls
(April 1993)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: DNS over TCP
From: Alexander Dupuy <dupuy @ hudson . cs . columbia . edu>
Date: Wed, 21 Apr 93 13:01:18 EDT
To: avalon @ coombs . anu . edu . au
Cc: firewalls @ GreatCircle . COM (Firewall Mailing List)
In-reply-to: Your message of Tue, 20 Apr 93 7:52:15 EST
Reply-to: dupuy @ hudson . cs . columbia . edu

> If zone transfers are a problem, why not use the BIND 4.8.3 source and
> just hack them out all together ?

Actually, bind 4.9, which just went into beta, has support for screening zone
transfers hacked in already.  This allows the administrator to specify those
networks or hosts from which zone transfers will be allowed.  Note that the
filtering is done at the DNS level, and does not arbitrarily block all DNS/TCP
connections, but only XFR requests.  This is especially helpful if you use the
IBM AIX version of netstat, which uses a TCP connection to the DNS nameserver
(apparently because it expects to make a lot of DNS queries).

The current beta is available via anonymous ftp from gatekeeper.dec.com.
Kudos to Paul Vixie at DECWRL for coordinating the bind 4.9 effort, and for
hacking the zone-transfer restriction so that it doesn't just block TCP
requests entirely.

@alex



Indexed By Date Previous: Re: Firewall protection software - TermServer?
From: dand @ qstar . com (Dan Dunn)
Next: ANNOUNCE: TAMU Security Tools Package
From: Douglas Lee Schales <drawbridge @ sc . tamu . edu>
Indexed By Thread Previous: Re: DNS over TCP
From: avalon @ coombs . anu . edu . au (Darren Reed)
Next: looking for....
From: pmetzger @ lehman . com (Perry E. Metzger)

Google
 
Search Internet Search www.greatcircle.com