DNS Ports

Kevin Darcy kcd at daimlerchrysler.com
Tue Jul 22 18:50:49 UTC 2003


Jonathan de Boyne Pollard wrote:

> DH> I am setting up Iptables [...]
>
> <URL:http://homepages.tesco.net./~J.deBoynePollard/FGA/dns-shaped-firewall-holes.html>
>
> DH> I know DNS uses UDP to send and get data.
>
> You need to un-learn this, because it is wrong.  See the
> web page for details.

Participants in the DNS protocol *do* use UDP to send and get data. Every single example
in your web page opens up holes for UDP. So in what sense is the original poster "wrong";
what, specifically, do they need to "un-learn"?


- Kevin




More information about the bind-users mailing list