Root server DNS traffic across Linux/ipchains firewall?

Joseph S D Yao jsdy at cospo.osis.gov
Thu Oct 21 22:08:22 UTC 1999


I'm afraid that most V8++ BINDs will be addressing you FROM random
ports [as many current network programs do] but always TO port 53.  You
might be well advised not to block on source ports, but only on
destination ports.

--
Joe Yao				jsdy at cospo.osis.gov - Joseph S. D. Yao
COSPO/OSIS Computer Support					EMT-B
-----------------------------------------------------------------------
This message is not an official statement of COSPO policies.


More information about the bind-users mailing list