>Oh my, someone else who is behind on his reading...?
>Yes, you do need to open TCP port 53. See the RFCs. Queries go over
>UDP by default. If the answer is too big to fit into the 512-byte UDP
>packet, they are retried over TCP. Zone transfers always use TCP. All
>to port 53.

Zone transfers are always TCP.  UDP is only used to check to see if a zone
transfer is needed before it happens, so you need both UDP and TCP access
through the firewalls for this to work.


