From: Arne Sagnes <ASagnes@Tickets.com>
To: NetFilter <netfilter@lists.samba.org>
Subject: Re: dns server
Date: 06 Jun 2002 10:36:32 -0400 [thread overview]
Message-ID: <1023374193.1070.14.camel@icewind.arne.net> (raw)
In-Reply-To: <200206061400.g56E0BA31175@vulcan.rissington.net>
DNS, specifically Bind, has options in the named.conf to limit zone
transfers and recursive lookups. You can use the 'allow-transfer { IP;
IP };' directive to restrict zone transfers.
Arne
On Thu, 2002-06-06 at 10:00, Antony Stone wrote:
> On Thursday 06 June 2002 2:48 pm, Raymond Leach wrote:
>
> > On Thursday 06 June 2002 15:45, Maciej Soltysiak wrote:
>
> > > Using netfilter you can not judge whether TCP:53 packet is a zone
> > > transfer or just a query.
> >
> > If you only expect to receive queries from internal interfaces then there
> > should be no 'queries' from external sources.
>
> Your statement is correct, however it does not help when you are running a
> domain name server which does need to be accessible from the outside, but you
> only want people to do standard lookups, and not zone transfers.
>
> I agree with Maciej - you should set appropriate access controls on the name
> server itself, because netfilter cannot do it for you.
>
>
> Antony.
--
Arne Sagnes - Email: asagnes@tickets.com
Work: +1 216 787 8613 - Cell: +1 216 577 2319
Be careful of reading health books, you might die of a misprint.
next prev parent reply other threads:[~2002-06-06 14:36 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-06-06 13:22 dns server Corin Langosch
2002-06-06 13:31 ` Francois Peyron
2002-06-06 13:37 ` Raymond Leach
2002-06-06 13:45 ` Maciej Soltysiak
2002-06-06 13:48 ` Raymond Leach
2002-06-06 14:00 ` Antony Stone
2002-06-06 14:36 ` Arne Sagnes [this message]
2002-06-06 15:06 ` Tony Earnshaw
2002-06-06 13:33 ` Antony Stone
2002-06-06 14:00 ` Daniel Bastos
2002-06-06 14:04 ` Tony Earnshaw
2002-06-08 9:58 ` Nick Drage
2002-06-09 7:40 ` Tony Earnshaw
-- strict thread matches above, loose matches on Subject: below --
2002-06-08 10:21 Corin Langosch
2002-06-08 22:36 ` Nick Drage
2004-02-20 23:52 DNS server Anshuman Singh Rawat
2004-02-21 0:22 ` Ray Olszewski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1023374193.1070.14.camel@icewind.arne.net \
--to=asagnes@tickets.com \
--cc=netfilter@lists.samba.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.