Re: Setting up SMTP for outbound mail only
- From: "Sanford Whiteman" <swhitemanlistens-software@xxxxxxxxxxxxxxxxxxxxx>
- Date: Tue, 04 Dec 2007 01:29:34 -0500
I found the following regarding UDP 53 and am wondering what your
thoughts are on this. Namely, if I open it will it be a security
risk?
No.
UDP 53 must be open to receive DNS responses. As UDP is
connectionless, there is no way to open only outbound UDP 53
connections. (Anything you think of as a UDP "connection" is a fake
state maintained by some firewalls across packets with reflexive
source and destination info.)
And, as is typical of newbie-sponsored sites like "AuditMyPC," their
assessment of TCP 53 is wrong. TCP 53 is used for normal DNS recursion
when responses are over UDP packet capacity, _not_ only for zone
transfer. However, outbound + stateful TCP 53 is all that is necessary.
Their assessment has the mild ring of truth in that you must ensure
that zone transfer is not possible from the Net at large. But [a]
opening outbound TCP 53 connections for DNS recursion does not mean
that inbound TCP 53 is open; and [b] even opening inbound TCP 53 does
not mean that you are opening zone transfers. All of these are
separate configuration areas in modern DNS servers.
--Sandy
------------------------------------
Sanford Whiteman, Chief Technologist
Broadleaf Systems, a division of
Cypress Integrated Systems, Inc.
------------------------------------
.
- Follow-Ups:
- Re: Setting up SMTP for outbound mail only
- From: Bill Fuller
- Re: Setting up SMTP for outbound mail only
- References:
- Setting up SMTP for outbound mail only
- From: Bill Fuller
- Re: Setting up SMTP for outbound mail only
- From: Sanford Whiteman
- Re: Setting up SMTP for outbound mail only
- From: Bill Fuller
- Re: Setting up SMTP for outbound mail only
- From: Sanford Whiteman
- Re: Setting up SMTP for outbound mail only
- From: Bill Fuller
- Re: Setting up SMTP for outbound mail only
- From: Sanford Whiteman
- Re: Setting up SMTP for outbound mail only
- From: Bill Fuller
- Re: Setting up SMTP for outbound mail only
- From: Sanford Whiteman
- Re: Setting up SMTP for outbound mail only
- From: Bill Fuller
- Re: Setting up SMTP for outbound mail only
- From: Sanford Whiteman
- Re: Setting up SMTP for outbound mail only
- From: Bill Fuller
- Setting up SMTP for outbound mail only
- Prev by Date: Re: Setting up SMTP for outbound mail only
- Next by Date: Re: Setting up SMTP for outbound mail only
- Previous by thread: Re: Setting up SMTP for outbound mail only
- Next by thread: Re: Setting up SMTP for outbound mail only
- Index(es):
Relevant Pages
|