Re: DNS queries with UDP and TCP



On 18.09.06 15:31, Alejandro wrote:
Hi people, I have some low rate problems in my network and I think it
could be the DNS servers from my ISP I use in my proxy (squid) installed
in a Debian Sarge machine, they are open DNS's and they could have a big
traffic load.

But also I have read on the web that some common resolution queries to
DNS servers and their responses use TCP because they need a bigger
amount of bytes (I'm not talking about zone transfer, I'm talking about
of direct and reverse simple name resolutions). So do you think in my
firewall I have to open TCP/53 and UDP/53 ports in order to have name
resolution to my proxy, or just opening UDP/53 port is enough ???

allowing ESTABLISHED connections from outside should just be enough. The
kernel keeps track of all TCP connections opened from inside and sent UDP
requests and allows the replies to come back.
--
Matus UHLAR - fantomas, uhlar@xxxxxxxxxxx ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
It's now safe to throw off your computer.


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



Relevant Pages

  • DNS queries with UDP and TCP
    ... But also I have read on the web that some common resolution queries to ... DNS servers and their responses use TCP because they need a bigger ... firewall I have to open TCP/53 and UDP/53 ports in order to have name ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: W2K3 - Forwarders/Root Hints
    ... >way to go due to the ISPs cache and faster resolution. ... >resolution fail for my clients or will W2K3 DNS fall back to using root ... >DNS servers, so four servers would have to be down before the lookups fail, ...
    (microsoft.public.windows.server.dns)
  • Re: KB Article 828731
    ... The EDNS0 issue was a separate issue from the slow response time. ... When I switched to using only our Win2003 DNS servers for external ... > Did this help your resolution problem? ...
    (microsoft.public.win2000.dns)
  • Re: Network share question
    ... >> I have made a check of the cables and seen nothing abnormal. ... > prove the DNS Servers are setup correctly. ... >> No problem at level of ping or and the name resolution is good. ... > nslookup hn016.Crelan.be 10.1.6.25 ...
    (microsoft.public.win2000.networking)
  • Re: Spooler subsystem app accessing DNS
    ... > name resolution to your ISP's DNS servers? ... TCP Port 135 is not used for NetBIOS name resolution. ...
    (comp.security.firewalls)