nat and dns

Jozsef Kadlecsik kadlec at blackhole.kfki.hu
Fri Sep 24 11:43:20 CEST 2004


On Thu, 23 Sep 2004, Jason Opperisano wrote:

> > Most DNS queries take place over UDP, however if the
> > reply to the query is especially large then a new TCP connection is
> > opened between the client and server.
>
> find me a response to a client resolver request that doesn't fit in a
> single UDP packet, and i'll stop seeing red every time i see someone
> recommend allowing TCP 53 from any IP to their DNS server (*).

AIX uses just TCP, even for a plain query.

Best regards,
Jozsef
-
E-mail  : kadlec at blackhole.kfki.hu, kadlec at sunserv.kfki.hu
PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
Address : KFKI Research Institute for Particle and Nuclear Physics
          H-1525 Budapest 114, POB. 49, Hungary



More information about the netfilter mailing list