[Prev][Next][Index][Thread]

PROXY DNS ???



Eddie Harari writes:
 >    the problem is that DNS use UDP datagrams , so when I try to resolve names
 >    I connect to one of the root servers and it's reply never get thrue my cisco
 >    so I know I can solve it by opening the udp connection ( and I have to open 
 >    all ports because there is no way to know on what port will the reply come on

Nope.

 1. There's a source port & a destination port.  One of them will be
    the DNS port.
 2. You can only allow packets coming from the DNS server, and to your
    dns server, and only going to your DNS server on the appropriate
    port.


Follow-Ups: References: