Re: forward and reverse dns lookups (not linux related)
Tim Holloway <timh-kiPKLF+HnOy1Z/[email protected]> Tue, 13 Nov 2012 15:56:40 -0500
| Newsgroups | gmane.org.user-groups.jaxlug |
|---|---|
| Message-ID | <[email protected]> |
DNS/RDNS should* be using udp. Port 53 tcp is for bulk operations like zone transfers. My firewall permits port 53 UDP from outside, but not port 53 tcp, since all the zone transfers are intranet. Actually, I had to put a throttle on port 53 UDP external inbound traffic as well, since in recent months I've seen several instances of being DDOS'ed because I was being exploited for DNS reflection attacks. Tim *Unless they aren't. On Fri, 2012-11-09 at 16:20 -0500, The Donald Cowart wrote: > Just off the top of my head, one is using TCP, the other UDP??? > > --DC > > > On Fri, Nov 9, 2012 at 4:17 PM, Robert Mckennon <[email protected]>wrote: > > > So...the issue is: > > > > Connected to the coorporate network via a vpn connection through our > > new cisco ASA, for some reason Forward DNS queries fail, but Reverse > > DNS queries work.... This is very baffling! > > > > I just can't image that the fire somehow is blocking forward lookups > > but allowing reverse lookups, when icmp and filesharing all work (at > > least via ip address). > > > > > > Any thoughts??? > > > > Rob. > > > > --------------------------------------------------------------------- > > Archive http://marc.info/?l=jaxlug-list&r=1&w=2 > > RSS Feed http://www.mail-archive.com/[email protected]/maillist.xml > > Unsubscribe [email protected] > > > > > > --------------------------------------------------------------------- Archive http://marc.info/?l=jaxlug-list&r=1&w=2 RSS Feed http://www.mail-archive.com/[email protected]/maillist.xml Unsubscribe [email protected]