named -- using which port?
Hi there,
I have just setting up a BIND server. when i activate the iptables allow ONLY TCP port 53(others all drop), the BIND server doesnt work well anymore. other than port 53, which port or any other thing i should open up? thanks. |
well DNS is 99% UDP... don't drop UDP/53.
|
Quote:
how about TCP/53? |
what about it... that'll be about 1% if that. TCP would only be a last resort for dns if the client even supports it. most dns servers won't listen for TCP at all.
|
Hi Acid_kewpie,
problem solved after i allow UDP/53. thanks very much for your support. icechong |
AFAIK TCP will be used for reliable long queries or for zone transfers.
So if you block TCP/53 you might get intermitent failures in case udp packets are reorderd. I wouldn't block TCP/53. rfc says that both transport methods can be used. |
All times are GMT -5. The time now is 01:14 PM. |