Re: Restricting zone transfer



"Kevin D. Goodknecht Sr. [MVP]" <admin@xxxxxxxxxxxxxx> wrote in message
news:OQodoVT0GHA.4808@xxxxxxxxxxxxxxxxxxxxxxx
jb6000 wrote:
Hello,

I have two DNS servers (ns1 and ns2).
If I want to restrict zone transfers to these two servers only, do I
do it from the primary DNS server (ns1) or do I do it on both (ns1 &
ns2)?

On the Primary. Zone transfers can also be allowed from the Secondary,
records can only be added/modified on the primary.


Adding/modifying records has nothing directly to do with
allowing or disallowing zone transfers.



--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]

--
Best regards,
Kevin D. Goodknecht Sr. [MVP]
Hope This Helps
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
http://support.wftx.us/
http://message.wftx.us/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================




.



Relevant Pages

  • Re: Restricting zone transfer
    ... I have two DNS servers (ns1 and ns2). ... If I want to restrict zone transfers to these two servers only, ...
    (microsoft.public.windows.server.dns)
  • DNS Server Configuration
    ... For my own personal interest I try to configure dns servers for one of our ... I use 2 dns servers (ns1 and ns2) one located in our office and the other ... Host" reply when I ping one of my machines. ...
    (comp.os.linux.networking)
  • Re: DNS traffic from DMZ to internal network - Is it vulnerable?
    ... Be sure to have 53 TCP blocked which is used for zone transfers. ... limit which internal computers have reverse lookups entries if this is ... and tighten access control lists on the DNS servers. ... > requirement for DNS reverse lookup for a server in the DMZ. ...
    (comp.security.misc)
  • Re: DNS traffic from DMZ to internal network - Is it vulnerable?
    ... Be sure to have 53 TCP blocked which is used for zone transfers. ... limit which internal computers have reverse lookups entries if this is ... and tighten access control lists on the DNS servers. ... > requirement for DNS reverse lookup for a server in the DMZ. ...
    (comp.security.firewalls)
  • Re: DNS traffic from DMZ to internal network - Is it vulnerable?
    ... > Be sure to have 53 TCP blocked which is used for zone transfers. ... > limit which internal computers have reverse lookups entries if this is ... > and tighten access control lists on the DNS servers. ... >> requirement for DNS reverse lookup for a server in the DMZ. ...
    (comp.security.firewalls)

Loading