Re: pf.conf newbie help

From: Danilo Kempf (usenet_at_nullpointer.de)
Date: 08/25/04


Date: Wed, 25 Aug 2004 15:00:30 +0200


> Ah, I was allowing port 53 as tcp, not udp. That is my error...

Dennis,

While passing traffic for UDP/53 will make your DNS lookups work, don't
delete your TCP/53 rule just yet.

Most of the time DNS is done via UDP, but it has a builtin limit. DNS
messages may/should not grow beyond 512 bytes. When they get longer, the
DNS server will truncate the result. Upon receiving a truncated result to a
DNS query, any sane resolver will retry the same query via TCP.

So to spare you some spurious errors, also pass TCP/53.

Regards, Danilo



Relevant Pages

  • Re: Dual NIC vs Single NIC
    ... Thank you for helping me to correct the misunderstand of DNS query process. ... Thank you again for your supplement about the client DNS cache issue. ... | server rather than using locally cached information may slow things down. ...
    (microsoft.public.windows.server.sbs)
  • Re: Confusing problem..Please help.
    ... I have a caching DNS server running on my server. ... whoever actually controls the IP address space sets up reverse DNS -- ... Recall that for an ordinary domain name, such as "public.com", its DNS address is resolved first by asking the hardcoded list of root domain servers, ".". ... They will not respond directly, but refer you to the domain servers that are authoritative for ".com", and they will refer you to the authoritative servers for ".public.com", which, presumably, will respond to the DNS query. ...
    (comp.mail.misc)
  • Changing machine startup sequence in the registry
    ... Currently the following procedure takes place during machine startup on XP/2003 clients in a domain: ... DNS servers, default gateway, etc. ... DNS query for domain controllers. ...
    (microsoft.public.windows.server.security)
  • help with DNS implimitation
    ... i try to make my own DNS "server". ... i'm working on a local network (not ... application (as a dns query). ... now any dns query will be send to the company real dns server. ...
    (microsoft.public.win2000.dns)
  • help with DNS implimitation
    ... i try to make my own DNS "server". ... i'm working on a local network (not ... application (as a dns query). ... now any dns query will be send to the company real dns server. ...
    (microsoft.public.win2000.dns)