<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BIND 9.2----everyone using this DNS in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098030#M573707</link>
    <description>Hi Tomek,&lt;BR /&gt;&lt;BR /&gt;I tried from my pc pointing another DNS server's IP, but I cannot resolve any host by that DNS!? I guess, that DNS server has some problem or allow hostsby IP addresses.&lt;BR /&gt;&lt;BR /&gt;What I understand( or mis-understand), my DNS's port 53 should be open to all, and rest should be blocked.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Richard</description>
    <pubDate>Tue, 21 Oct 2003 03:45:32 GMT</pubDate>
    <dc:creator>Rgomes</dc:creator>
    <dc:date>2003-10-21T03:45:32Z</dc:date>
    <item>
      <title>BIND 9.2----everyone using this DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098026#M573703</link>
      <description>Hi All,&lt;BR /&gt;&lt;BR /&gt;I have a DNS server( in the internet), ver is BIND 9.2.&lt;BR /&gt;&lt;BR /&gt;I understand, anyone can use my DNS server for name resulation by pointing DNS setting in their OS( win98, winXP). How can I stop this behavior of my DNS server. I want only users from my network will use it.&lt;BR /&gt;&lt;BR /&gt;Is this scenario ok, or anything else? Need your suggestions.&lt;BR /&gt;&lt;BR /&gt;TIA,&lt;BR /&gt;&lt;BR /&gt;Richard</description>
      <pubDate>Tue, 21 Oct 2003 02:57:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098026#M573703</guid>
      <dc:creator>Rgomes</dc:creator>
      <dc:date>2003-10-21T02:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: BIND 9.2----everyone using this DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098027#M573704</link>
      <description>Block incoming port 53 (UDP) on router&lt;BR /&gt;&lt;BR /&gt;-Tomek</description>
      <pubDate>Tue, 21 Oct 2003 03:04:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098027#M573704</guid>
      <dc:creator>Tomek Gryszkiewicz</dc:creator>
      <dc:date>2003-10-21T03:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: BIND 9.2----everyone using this DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098028#M573705</link>
      <description>Hi Tomek,&lt;BR /&gt;&lt;BR /&gt;Thanks for your reply.&lt;BR /&gt;&lt;BR /&gt;Won't it block all users name-resulation related querries by denying all incoming request on port 53 on router?&lt;BR /&gt;&lt;BR /&gt;It is an ISP DNS.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Richard</description>
      <pubDate>Tue, 21 Oct 2003 03:20:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098028#M573705</guid>
      <dc:creator>Rgomes</dc:creator>
      <dc:date>2003-10-21T03:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: BIND 9.2----everyone using this DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098029#M573706</link>
      <description>Oh, if it is ISP, it should be opened.&lt;BR /&gt;BTW why to deny all the world to use your DNS? &lt;BR /&gt;&lt;BR /&gt;-Tomek</description>
      <pubDate>Tue, 21 Oct 2003 03:30:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098029#M573706</guid>
      <dc:creator>Tomek Gryszkiewicz</dc:creator>
      <dc:date>2003-10-21T03:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: BIND 9.2----everyone using this DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098030#M573707</link>
      <description>Hi Tomek,&lt;BR /&gt;&lt;BR /&gt;I tried from my pc pointing another DNS server's IP, but I cannot resolve any host by that DNS!? I guess, that DNS server has some problem or allow hostsby IP addresses.&lt;BR /&gt;&lt;BR /&gt;What I understand( or mis-understand), my DNS's port 53 should be open to all, and rest should be blocked.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Richard</description>
      <pubDate>Tue, 21 Oct 2003 03:45:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098030#M573707</guid>
      <dc:creator>Rgomes</dc:creator>
      <dc:date>2003-10-21T03:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: BIND 9.2----everyone using this DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098031#M573708</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Let us assume that your Internal network address is 10.0.0.0/8.&lt;BR /&gt;&lt;BR /&gt;Edit /etc/named.conf and put allow-recursion directive.&lt;BR /&gt;&lt;BR /&gt; options { &lt;BR /&gt;directory "/var/named"; &lt;BR /&gt;allow-recursion { 10.0.0.0/8; }; &lt;BR /&gt;           };&lt;BR /&gt;&lt;BR /&gt;Restart named .&lt;BR /&gt;&lt;BR /&gt;Now the Resolution of external domains will be only done for the clients having source IP address in your network viz 10.x.x.x&lt;BR /&gt;&lt;BR /&gt;Anybody who try to use your DNS server for resolving external domains ( other than your own domain ) from Internet will not able to do that.&lt;BR /&gt;&lt;BR /&gt;I recommend you to put this restriction for recursive lookup's , as sophisticated attacks like Birthday attack can be used to poison your DNS server's cache with false records.&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;&lt;BR /&gt;U.SivaKumar&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Oct 2003 04:21:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098031#M573708</guid>
      <dc:creator>U.SivaKumar_2</dc:creator>
      <dc:date>2003-10-21T04:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: BIND 9.2----everyone using this DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098032#M573709</link>
      <description>Hi Shivakumar,&lt;BR /&gt;&lt;BR /&gt;In BIND 9.2 doc. I have seen ip_add_access list. Where does it differ between this two, I mean, access-list and recursive directive?&lt;BR /&gt;&lt;BR /&gt;Thanks and best regards&lt;BR /&gt;Richard</description>
      <pubDate>Tue, 21 Oct 2003 12:15:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098032#M573709</guid>
      <dc:creator>Rgomes</dc:creator>
      <dc:date>2003-10-21T12:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: BIND 9.2----everyone using this DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098033#M573710</link>
      <description>Hi SivaKumar,&lt;BR /&gt;&lt;BR /&gt;The DNS server is up and running. As I like to restrict other users outside of this ISP network, so they won't able to use my DNS server. Now my named.conf file looks like this as per your suggestion:&lt;BR /&gt;&lt;BR /&gt;--------------------------------------------&lt;BR /&gt;options {&lt;BR /&gt;&lt;BR /&gt;        check-names response fail;      // do not change this&lt;BR /&gt;&lt;BR /&gt;        check-names slave warn;&lt;BR /&gt;&lt;BR /&gt;        directory "/etc/named.data";&lt;BR /&gt;&lt;BR /&gt;        query-source address * port 53; (note: I uncommented this. It was preceded by a # in original output)&lt;BR /&gt;&lt;BR /&gt;        version "not a chance!!";&lt;BR /&gt;&lt;BR /&gt;        allow-recursion { 203.112.192.0/20; 209.58.24.0/24:  };&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;};&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;zone "db.my.net" {&lt;BR /&gt;&lt;BR /&gt;        type master;&lt;BR /&gt;&lt;BR /&gt;        file "db.mynet";&lt;BR /&gt;&lt;BR /&gt;        allow-transfer { none; };&lt;BR /&gt;--------------------------------------------&lt;BR /&gt;&lt;BR /&gt;Does this configuration also restricts other Internet DNS servers( out of ISP network) to query our DNS server? As this DNS server is an ISP DNS server and connected to internet 24x7, what it should be?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance,&lt;BR /&gt;Richard&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 02 Nov 2003 05:00:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098033#M573710</guid>
      <dc:creator>Rgomes</dc:creator>
      <dc:date>2003-11-02T05:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: BIND 9.2----everyone using this DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098034#M573711</link>
      <description>A firewall controlls access from the Internet to your organization.  Blocking port 53 on the Internet will not block your organization from doing DNS.  It will block the public from doing lookups on your BIND server.&lt;BR /&gt;&lt;BR /&gt;This is okay,unless you have an external webserver and this BIND machine is supposed to provide DNS services for it.  If so, you can't shut port 53.&lt;BR /&gt;&lt;BR /&gt;More on that: A firewall has the equivalent of two NIC cards.  Mine is actually a Linux box with two cards. The firewall setttings for eth0 the external card are much more restrictive than for the internal network eth1. The Linux iptables firewall and most others let you distinguish between internal and external services.&lt;BR /&gt;&lt;BR /&gt;Depending on what you put on your DNS server, the fact that everyone CAN use it is meaningless.  Unless there is a record on the main Internic database pointing to it, nobody will need or want to use it.&lt;BR /&gt;&lt;BR /&gt;I have a record in the database that points my 13 customers domain names to look at my server.  Anyone else that wants can try, but those requests will get passed right back up toward teh root of the Internet.&lt;BR /&gt;&lt;BR /&gt;By pounding my server will millions of requests, it is theoretically possible to do a denial of service attack on the web servers of my legitimate customers.&lt;BR /&gt;&lt;BR /&gt;So, I have port 53 selectively blocked so that only valid requests can come through.  If its not valid for my domains the request is ignored at very little cpu and band width cost.&lt;BR /&gt;&lt;BR /&gt;I have details, but you'll need to refine your question for me to help any more.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Sun, 02 Nov 2003 12:04:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098034#M573711</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-11-02T12:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: BIND 9.2----everyone using this DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098035#M573712</link>
      <description>Hi SEP,&lt;BR /&gt;&lt;BR /&gt;Thanks for your reply. As I can see, you are giving so much valuable suggestions everyday on very different subject area, I must again thank you.&lt;BR /&gt;&lt;BR /&gt;Whatever, I allow users of my ISP only to use my DNS server by 'allow-recursion' statement in named.conf file. This is ok and I tested it as 'user from another ISP', and it worked, my DNS server didn't allow me to browse. &lt;BR /&gt;&lt;BR /&gt;Fine, now I want to be clear myself on one thing, I have a website &lt;A href="http://www.mynet.com" target="_blank"&gt;www.mynet.com&lt;/A&gt; and it's record is in my DNS server. Suppose user2 from another ISP want to browse this page. Can he able to resolve this site &lt;A href="http://www.mynet.com," target="_blank"&gt;www.mynet.com,&lt;/A&gt; as his ISP's DNS server does not have the record of &lt;A href="http://www.mynet.com." target="_blank"&gt;www.mynet.com.&lt;/A&gt; Would user2's request go directly to Internic, or how this kind of request will be resolved? Will it conflict with 'allow-recursion' statement in named.conf file?&lt;BR /&gt;I know, this is very fundamental question, but I need to be clear of this thing.&lt;BR /&gt;&lt;BR /&gt;Thanks a lot,&lt;BR /&gt;Richard</description>
      <pubDate>Sun, 02 Nov 2003 13:20:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/bind-9-2-everyone-using-this-dns/m-p/3098035#M573712</guid>
      <dc:creator>Rgomes</dc:creator>
      <dc:date>2003-11-02T13:20:03Z</dc:date>
    </item>
  </channel>
</rss>

