Security Basics mailing list archives

RE: TCP DNS requests


From: "Larry R." <lbrlove () bellsouth net>
Date: Wed, 30 Oct 2002 20:14:22 -0500

TCP would only be used for zone transfers or extraordinarily long DNS
replies (e.g. multiple record returns exceeding something like 512 bytes).
For my servers, I turn off TCP (via filters) for anything except machines to
which I allow transfers.

Hope this helps!

Larry

-----Original Message-----
From: Carl R Diliberto [mailto:cdiliberto () hotmail com]
Sent: Wednesday, October 30, 2002 8:46 AM
To: security-basics
Subject: TCP DNS requests


We are reporting TCP based DNS requests to one of our DNS servers coming
from internal, client IP addresses.  My manager would like to block the TCP
packets.  What or why would their be random TCP packets?  We monitored
several clients and it appears it only needs UDP.

Thanks
Carl


Current thread: