LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-15-2007, 10:32 AM   #1
rolandpish
Member
 
Registered: May 2007
Posts: 30

Rep: Reputation: 0
DNS Question


Hi everyone.

I'm doing some tests in order to host my own site. I haven't registered a domain yet since I'm in a test phase.
My test site (mytest.com) is hosted on my linux box (debian). Apache Web server and DNS server (bind9) are up an running.

My question is related to DNS.

On the local network everything is working great. On a windows xp box I point the DNS server to the local IP address of the linux box. After waiting around 1 minute if I go to http://mytest.com I get the corresponding html page hosted on the linux box.

Now I'm trying to do some tests from outside of the local network.
Before doing this I forwarded the corresponding ports on the router:
53 (DNS)
80 (HTTP)
and pointed them to the linux box local ip address.
Ok. In an outside network I changed the DNS server of a windows xp box and pointed it to the public IP address where the linux box is.
If I go to: http://xxxx.xxxx.xxxx.xxxx (xxxx.xxxx.xxxx.xxxx = public ip address) the web server works correctly and serves the incoming request on port 80 and shows the corresponding html page. But if I go to http://mytest.com firefox says: time limit exceeded (after 30 seconds trying to connect to mytest.com)

I would like to ask if it is possible to test this resolution name process over the internet without registering a domain name on any registrar (I don't want to register a domain name yet because these are just tests I'm doing now).

Thanks in advance

Best regards
 
Old 08-15-2007, 10:58 AM   #2
thebouv
Member
 
Registered: Aug 2007
Distribution: RHEL, Fedora, Ubuntu
Posts: 64

Rep: Reputation: 16
DNS resolution occurs over UDP and doesn't just use port 53. Look here for more information:

http://www.softpanorama.org/DNS/dns_ports.shtml

Note the section that says:

Quote:
Permitting only port 53 in and out is a broken firewall configuration
unless you specifically configure named to only talk on port 53. Doing
that is probably a mistake, because you significantly limit the space of
host-port-sequence number combinations. Limiting yourself to only port
53 outbound actually reduces the security of your DNS infrastructure.
 
Old 08-15-2007, 01:36 PM   #3
rolandpish
Member
 
Registered: May 2007
Posts: 30

Original Poster
Rep: Reputation: 0
Thanks a lot for your reply thebouv.
I'll read that document carefully and see what happens.

Best regards
 
Old 08-16-2007, 02:18 PM   #4
malx
LQ Newbie
 
Registered: Jul 2006
Location: Tasikmalaya City, West Java, Indonesia
Distribution: Slackware Linux
Posts: 2

Rep: Reputation: 0
Dear all,

To the point sir,
I 've read about issue of security DNS, the package is bind...
Quote:
The first issue which allows remote attackers to make recursive queries only
affects Slackware 12.0. More details about this issue may be found in the
Common Vulnerabilities and Exposures (CVE) database:
And it's link about that issue Issue
So, now I wanna get some tips how to make our DNS Server has higher security than before.
If one of yuo have a link, please give me.... I wanna learn more about the security....
This is for our future....It's important things.

Thank's

Best Regard's:

--Malx--

I'm sorry if my question bad...I'm newbie
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
DNS Question... bfloeagle Linux - Newbie 7 03-29-2006 10:32 AM
DNS question ec3042 Linux - Networking 1 12-24-2005 04:18 AM
DNS question jamrock Linux - Networking 2 05-15-2003 11:05 PM
dns question -- new to dns gadhiraju Linux - Networking 7 05-09-2001 05:59 PM
dns question -- new to dns gadhiraju Linux - General 2 05-09-2001 07:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 11:09 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration