Re: Issue with port blocking on public DNS server
- From: "Kevin D. Goodknecht Sr. [MVP]" <admin@xxxxxxxxxxxxxx>
- Date: Sun, 6 Aug 2006 17:40:47 -0500
WimVM wrote:
Hello,
I have two public DNS servers running Windows 2003 Web Edition SP1.
They are used as DNS server for hosting public domain names. On the
same servers I have a mailserver running (MailEnable). I also do port
filtering on the public network card (advanced options of the NIC).
I have these ports open:
-TCP: 25/53/110
-UDP: 53
-IP: 6/8/17
Everything works fine, except that I can not resolve external domain
names (other then the domain names in my own DNS server) on the
servers. This is ofcourse a requirement for the mail server...
When I scan the ports used by DNS I note that it is not only using
ports TCP53 and UDP53 but also DYNAMIC assign ports: 2 UDP and 1 TCP.
They mostly are something like 1028 (TCP) and 1025/1026/1027(UDP).
The problem is ofcourse that I can not block the ports in this way.
As soon as the ports are changed (after reboot?), name resolution
will fail.
How can I solve this? How can I still use port filtering and resolve
domain names without any problems.
Packet filtering on the interface, does not work as expected if you make
outbound connections from the machine. The interface packet filtering blocks
ports outbound as well as inbound. If this server is only used for DNS and
no outbound connections, including web browsing are done from this machine
you can force DNS to use a send on port 53.
813965 - Description of DNS registry entries in Windows 2000 Server, part 3
of 3: http://support.microsoft.com/default.aspx?kbid=813965
--
Best regards,
Kevin D. Goodknecht Sr. [MVP]
Hope This Helps
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
http://support.wftx.us/
https://secure.lsaol.com/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================
.
- References:
- Issue with port blocking on public DNS server
- From: WimVM
- Issue with port blocking on public DNS server
- Prev by Date: Re: AD-Integrated DNS - Root Hints, Forwarders, Confused!
- Next by Date: Re: Domain cannot be contacted?
- Previous by thread: Re: Issue with port blocking on public DNS server
- Next by thread: Re: VPN and DNS issue
- Index(es):
Relevant Pages
|