From owner-freebsd-ipfw@FreeBSD.ORG Sun Dec 28 23:07:25 2003 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1B55F16A4CE for ; Sun, 28 Dec 2003 23:07:25 -0800 (PST) Received: from mailbox.wingercom.dk (mailbox.easyspeedy.dk [81.19.240.4]) by mx1.FreeBSD.org (Postfix) with ESMTP id 7C99143D55 for ; Sun, 28 Dec 2003 23:07:21 -0800 (PST) (envelope-from per@xterm.dk) Received: from mailbox.wingercom.dk (localhost [127.0.0.1]) by mailbox.wingercom.dk (Postfix) with SMTP id 0FBCB931AF; Mon, 29 Dec 2003 08:11:24 +0100 (CET) Received: from 62.242.151.142 (SquirrelMail authenticated user per) by mailbox.wingercom.dk with HTTP; Mon, 29 Dec 2003 08:11:24 +0100 (CET) Message-ID: <34589.62.242.151.142.1072681884.squirrel@mailbox.wingercom.dk> Date: Mon, 29 Dec 2003 08:11:24 +0100 (CET) From: "Per Engelbrecht" To: In-Reply-To: References: X-Mailer: SquirrelMail (version 1.2.5) MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: 8bit cc: freebsd-ipfw@freebsd.org Subject: Re: need testers for a ipfw rule generation script! X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 29 Dec 2003 07:07:25 -0000 Hi Bjoern, Boris, et al On certain occasions I've seen TCP query's (!) in my log . Don't ask me why, but a thread on the bind-list (a year ago or so) described how someMS-clients used TCP and not UDP to query a DNS server. If you read RFC 1034/1035 you will see that zone-transfer between servers is always TCP,while a query is "always" on UDP. I allow both TCP and UDP query in my firewall ruleset on my public DNS servers for the same reason. /per per@xterm.dk > On Mon, 29 Dec 2003, Boris Staeblow wrote: > >> On Sonntag, 28. Dezember 2003 23:27, Bjoern A. Zeeb wrote: >> >> > DNS can also be TCP. >> > (noted by a colleague who seemed to have a closer look at it). >> >> under which circumstances is a DNS TCP connection needed? >> (I´ve never used a DNS TCP rule before - without any problem) > > I I remember correctly it's RFC 1035 /Transport > > -- > Bjoern A. Zeeb bzeeb at Zabbadoz dot NeT > 56 69 73 69 74 http://www.zabbadoz.net/ > _______________________________________________ > freebsd-ipfw@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-ipfw > To unsubscribe, send any mail to > "freebsd-ipfw-unsubscribe@freebsd.org"