Great Circle Associates Firewalls
(July 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: cisco packet filter firewall
From: Brent @ GreatCircle . COM (Brent Chapman)
Date: Thu, 6 Jul 1995 23:23:42 -0800
To: David Madole/TMG/CSC <David_Madole/TMG/CSC . CSC @ cscmail . csc . com>, firewalls <firewalls @ greatcircle . com>
Cc: Julie Ann Connary <73203 . 2236 @ compuserve . com>

At 9:57 PM 7/6/95, David Madole/TMG/CSC wrote:
>By the way, DNS only uses TCP for zone transfers, so unless you are running a
>secondary nameserver on the other side of your firewall, you do not need (or
>want) the permit TCP lines in the filter.

This is true for UNIX implementations of DNS (i.e., BIND), but not
necessarily true in general.  In fact, it's not even true for all versions
of BIND, I don't think; I believe (though my info may be out of date) that
IBM AIX systems always use TCP connections for DNS, even for simple
resolver queries that most other UNIX systems would use UDP for.

Basicly, in order to fully support DNS, you have to support both UDP and
TCP queries.


-Brent

----------------------------------------------------------------------
For info about the Internet Security Firewalls Tutorial and a schedule
of upcoming dates, please send email to Tutorial-Info @
 GreatCircle .
 COM
----------------------------------------------------------------------
Brent Chapman                                 Great Circle Associates
Brent @
 GreatCircle .
 COM                         1057 West Dana Street
+1 415 962 0841                               Mountain View, CA  94041




Follow-Ups:
Indexed By Date Previous: Re: chroot & CERN httpd
From: mdr @ vodka . sse . att . com
Next: Re: xdmcp info
From: emwmf @ emw . ericsson . se (Martin Fredriksson)
Indexed By Thread Previous: Re: cisco packet filter firewall
From: David Madole/TMG/CSC <David_Madole/TMG/CSC . CSC @ cscmail . csc . com>
Next: Re: cisco packet filter firewall
From: Adam Safier <asafier @ explorer . csc . com>

Google
 
Search Internet Search www.greatcircle.com