DNS queries with UDP and TCP



Hi people, I have some low rate problems in my network and I think it
could be the DNS servers from my ISP I use in my proxy (squid) installed
in a Debian Sarge machine, they are open DNS's and they could have a big
traffic load.

But also I have read on the web that some common resolution queries to
DNS servers and their responses use TCP because they need a bigger
amount of bytes (I'm not talking about zone transfer, I'm talking about
of direct and reverse simple name resolutions). So do you think in my
firewall I have to open TCP/53 and UDP/53 ports in order to have name
resolution to my proxy, or just opening UDP/53 port is enough ???

Thanks a lot,


Alejandro


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



Relevant Pages

  • Re: DNS queries with UDP and TCP
    ... But also I have read on the web that some common resolution queries to ... DNS servers and their responses use TCP because they need a bigger ... resolution to my proxy, or just opening UDP/53 port is enough ??? ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: W2K3 - Forwarders/Root Hints
    ... >way to go due to the ISPs cache and faster resolution. ... >resolution fail for my clients or will W2K3 DNS fall back to using root ... >DNS servers, so four servers would have to be down before the lookups fail, ...
    (microsoft.public.windows.server.dns)
  • Re: KB Article 828731
    ... The EDNS0 issue was a separate issue from the slow response time. ... When I switched to using only our Win2003 DNS servers for external ... > Did this help your resolution problem? ...
    (microsoft.public.win2000.dns)
  • Re: Network share question
    ... >> I have made a check of the cables and seen nothing abnormal. ... > prove the DNS Servers are setup correctly. ... >> No problem at level of ping or and the name resolution is good. ... > nslookup hn016.Crelan.be 10.1.6.25 ...
    (microsoft.public.win2000.networking)
  • Re: Spooler subsystem app accessing DNS
    ... > name resolution to your ISP's DNS servers? ... TCP Port 135 is not used for NetBIOS name resolution. ...
    (comp.security.firewalls)