Re: TCP/IP Filter Break Local DNS

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



"John" <nospam@xxxxxxxxxx> wrote in message
news:eI#sPuUNFHA.4092@xxxxxxxxxxxxxxxxxxxxxxx
> I have a Win2k server, all patches up to date. I want to use TCP/IP
> filtering to increase the security of this server. DNS service is
installed
> locally and is only to be utilized for the server itself to resolve
domains.


> Essentially it's a caching resolver DNS with no forward domains.

Ok, but that is unnecessary in Win2000 since the DNS
client itself provides it's own caching (even in the server
product.)

You are actually arranging to cache twice which is likely
slower (than caching once.)

> All functions correctly until I enable UDP filtering within TCP/IP
> Filtering. As soon as this is enabled the server can no longer query the
DNS
> server that is installed directly on it. I allowed port 53 for UDP and TCP
> with no effect.

Where did you "enable filtering"? What product or interface?

If you enabled 53 UDP & TCP correctly then it would not
interfere with DNS queries.

> Any ideas? I would rather not keep all UDP ports open.

You don't need to do that, but we must know more about
HOW you created this filter?

IPSec? RRAS? NIC filters (ugh!)? Third party firewall?


.



Relevant Pages

  • Re: AOL - Transaction Failed
    ... Note that a 512-octet UDP payload requires a 576-octet IP ... to enable/disable the DNS fixup. ... This feature is added to the fixup protocol command in the PIX Firewall ... > their server with explination. ...
    (microsoft.public.exchange.admin)
  • Re: DNS & using the TCP/IP FIlter
    ... The problem is dns to the internet dns servers uses udp port 53 "outbound" NOT ... Unfortunately udp IP filtering can not keep track of the state of a ...
    (microsoft.public.win2000.security)
  • Re: TCP/IP Filtering Problem
    ... Unlike tcp/ip filtering for TCP, filtering for UDP is not "stateful" in that the ... dns name resolution FROM your server. ... I have it set so that the following TCP ports are ...
    (microsoft.public.win2000.security)
  • Re: Satellite Branch Office Woes
    ... servers in the SBO) for several small locations that will be coming online ... certain traffic (especially RPCs, DNS, and other things the DCs need)? ... Also, if he is filtering, even loosely, expect RPC issues which don't filter ... DNS Server which can resolve all of the AD records. ...
    (microsoft.public.windows.server.active_directory)
  • Re: SMTP Woes
    ... Do you host the DNS for your external domain or is this done by your ISP ... The volume of connections your getting presuming these have ... Have you made any other changes to your network, mail server, DNS ... filtering software. ...
    (microsoft.public.exchange.admin)