refresh: failure, after setting up new bind bind-9.2.0 server

Barry Margolin barmar at genuity.net
Wed Mar 27 21:24:47 UTC 2002


In article <a7tane$keq at pub3.rc.vix.com>,
Brett A. Hansen <brett at annis.com> wrote:
>Yes, I am very strict with our firewall rules.  I only allow our slave
>servers access to TCP port 53, and the world access to UDP port 53.

What about UDP traffic to the slave server?  Do you allow the replies from
the master server?  The destination port of these is a random high port,
unless you use the 'query-source * port 53' option.

-- 
Barry Margolin, barmar at genuity.net
Genuity, Woburn, MA
*** DON'T SEND TECHNICAL QUESTIONS DIRECTLY TO ME, post them to newsgroups.
Please DON'T copy followups to me -- I'll assume it wasn't posted to the group.


More information about the bind-users mailing list