Re: ISA Always Blocks DNS Zone Transfers



I normally use transfer to selected servers only, but I am performing a
temporary tests to eliminate all variables.

I do allow both TCP Incoming and Receive Send UDP. All TCP requests are
denied for some reason. I even split the UDP and TCP traffic so I could
better track it. So far all UDP queries are working, but no TCP zone
transfers are working.

My DNS server is on a NAT network, but published with Internet information.
Maybe the NAT is inteferring with the Zone Transfer.

"Jens Baier" wrote:

Hi,

My DNS server is configured to perform a zone transfer to ANY server.

You should change this setting only to allowed DNS Servers!

The DNS Server publishing rule does allow incoming TCP connections. Why
does it
continue to deny incoming DNZ Zone transfer connections from the Internet?

DNS zone transfer uses TCP instead of UDP. Have you check your rules /
protocol definition?
ISA logging should show you the denied conenctions and the reason for that

--
Gruss Jens
www.it-training-grote.de/blog
www.it-training-grote.de
www.nt-faq.de


.



Relevant Pages

  • Re: ISA Always Blocks DNS Zone Transfers
    ... It sounds like you are focusing everything on "inbound" (Publishing) and not ... I do allow both TCP Incoming and Receive Send UDP. ... Maybe the NAT is inteferring with the Zone Transfer. ...
    (microsoft.public.isaserver)
  • Re: [FATAL] Kerberos does not have a ticket for <any of my servers>
    ... they should be using TCP. ... Most of the Local servers I've been able to get the Kerberos to pass by ... I'm rebooting the Exchange 2003 Server now to get it update as well as the ...
    (microsoft.public.win2000.active_directory)
  • Re: Server with UDP and TCP
    ... servers using TCP. ... servers use UDP. ... TCP sockets and the same time. ... same issue occurs if i use the UDP recvfrom comand. ...
    (comp.lang.c)
  • Re: Updates
    ... forces the max tcp window size to 64k. ... This turns off Receive Window Auto-Tuning, and prevents vista ... slow (but only when communicating with the two 2k3 sp2 servers). ...
    (microsoft.public.cert.exam.mcse)
  • Server with UDP and TCP
    ... servers using TCP. ... servers use UDP. ... TCP sockets and the same time. ... same issue occurs if i use the UDP recvfrom comand. ...
    (comp.lang.c)