About "update" packets

Maurizio Colella Maurizio.Colella at marconi.com
Wed Jun 16 11:36:50 UTC 2004


Dear all,
I'm having some problem with some clients that from internet try to
"update" my DNS (9.2.3) ! (..Hackers ?)
I need to make the update only from my machine, so i've configured my
named.conf to use "allow-update" and "key stantement".
At the moment my DNS "denied" any update from all clients that are not
compliant (..ip-address and key are not correct !!), in add, i've also
closed all TCP  packets from any to my DNS, becose i've suppose that
"update" are performed only by TCP, but I see that "update" are always
present ! So , my simply question is: Are in UDP packets the "nsupdate"
??.. Have you some suggestions for ??
Thanks very much, in advance !
Regards




More information about the bind-users mailing list