1833755 Members
2884 Online
110063 Solutions
New Discussion

Securing HP-UX DNS

 
Michael_423
Occasional Contributor

Securing HP-UX DNS

We have one DNS server on our network that all the Asian root servers love to send binaries to over port 53. Hence I have the following 2 questions.

2 Questions:

1) Is there a way we can secure the DNS server to reject a DNS response with binary code in it?

2) Is there really some legimate DNS traffic to a BIND server that should be from a root server? Or in other words, is there going to be any problems if we start blocking this type of traffic.

Michael
1 REPLY 1
Steven Sim Kok Leong
Honored Contributor

Re: Securing HP-UX DNS

Hi,

SANS is one of the best security resources.

Check out this link for DNS security issues you would want to be concerned with:
http://www.sans.org/rr/catindex.php?cat_id=17

Hope this helps. Regards.

Steven Sim Kok Leong