DNS bind security question

"Rob Francis" <[email protected]> Wed, 19 Mar 2003 10:44:14 +1200
Newsgroups gmane.linux.redhat.security.server
Message-ID <[email protected]>
This is a multi-part message in MIME format.

------=_NextPart_000_0066_01C2EE04.7C0E5870
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit

Hi,

I am a long time Windows systems administrator and developer who is moving
to Linux - so treat me as a newbie. A have just had fibre-optic cable
connected at work and setup a multihomed Linux firewall with connections to
the Internet, internal LAN (NAT), and a DMZ area. I'm using iptables
successfully to firewall at this main junction.

In the DMZ area I have two DNS boxes running RedHat 8. I have setup one box
as a master and the other as a slave. Both have iptables running locally to
limit the ports to ICMP traffic, 53 and 80. If I try the host command to
test my DNS configuration it only works when I open up the firewall but
gives connection timed out otherwise. I have port 53 open for both udp and
tcp, as well as covering INPUT and OUTPUT chains. I noticed in the log file
reference to port 953 for named command so tried adding that also. What
other ports do I need to open yet remain fairly secure?

Also restarting the named service often is troublesome (unlike say
iptables). Is that a bind issue. I have tried from both the Services GUI and
also from the command line:
/sbin/service named restart

What is wrong?

Thanks,
Rob

------=_NextPart_000_0066_01C2EE04.7C0E5870
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2600.0" name=3DGENERATOR></HEAD>
<BODY>
<DIV><FONT face=3D"Century Gothic" size=3D2><SPAN=20
class=3D824344221-18032003>Hi,</SPAN></FONT></DIV>
<DIV><FONT face=3D"Century Gothic" size=3D2><SPAN=20
class=3D824344221-18032003></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=3D"Century Gothic" size=3D2><SPAN =
class=3D824344221-18032003>I am a=20
long time Windows systems administrator and developer who is moving to =
Linux -=20
so treat me as a newbie. A have just had fibre-optic cable connected at =
work and=20
setup a multihomed Linux firewall with connections to the Internet, =
internal LAN=20
(NAT), and a DMZ area. I'm using iptables successfully to firewall at =
this main=20
junction.</SPAN></FONT></DIV>
<DIV><FONT face=3D"Century Gothic" size=3D2><SPAN=20
class=3D824344221-18032003></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=3D"Century Gothic" size=3D2><SPAN =
class=3D824344221-18032003>In the=20
DMZ area I have two DNS boxes running RedHat 8. I have setup one box as =
a master=20
and the other as a slave. Both have iptables running locally to limit =
the ports=20
to ICMP traffic, 53 and 80. If I try the host command to test my DNS=20
configuration it only works when I open up the firewall but gives =
connection=20
timed out otherwise. I have port 53 open for both udp and tcp, as well =
as=20
covering INPUT and OUTPUT chains. I noticed in the log file reference to =
port=20
953 for named command so tried adding that also. What other ports do I =
need to=20
open yet remain fairly secure?</SPAN></FONT></DIV>
<DIV><FONT face=3D"Century Gothic" size=3D2><SPAN=20
class=3D824344221-18032003></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=3D"Century Gothic" size=3D2><SPAN =
class=3D824344221-18032003>Also=20
restarting the named service often is troublesome (unlike say iptables). =
Is that=20
a bind issue. I have tried from both the Services GUI and also from the =
command=20
line:</SPAN></FONT></DIV>
<DIV><FONT face=3D"Century Gothic" size=3D2><SPAN=20
class=3D824344221-18032003>/sbin/service named =
restart</SPAN></FONT></DIV>
<DIV><FONT face=3D"Century Gothic" size=3D2><SPAN=20
class=3D824344221-18032003></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=3D"Century Gothic" size=3D2><SPAN =
class=3D824344221-18032003>What is=20
wrong?</SPAN></FONT></DIV>
<DIV><FONT face=3D"Century Gothic" size=3D2><SPAN=20
class=3D824344221-18032003></SPAN></FONT>&nbsp;</DIV>
<DIV><FONT face=3D"Century Gothic" size=3D2><SPAN=20
class=3D824344221-18032003>Thanks,</SPAN></FONT></DIV>
<DIV><FONT face=3D"Century Gothic" size=3D2><SPAN=20
class=3D824344221-18032003>Rob</SPAN></FONT></DIV></BODY></HTML>

------=_NextPart_000_0066_01C2EE04.7C0E5870--