3 ms·
For some it's a matter of knowing that they shouldn't be running a recursive server. We recently contacted a number of customers asking them to disable their r
by devicenull 14y ago
For some it's a matter of knowing that they shouldn't be running a recursive server. We recently contacted a number of customers asking them to disable their recursive server, and most didn't really know they were running it, or that it was a problem.
- acqq 14y agoIn my a-few-guys-in-one-office location we have a Windows domain server which has also a DNS server to which our computers are connected. I don't have the slightest idea if that DNS server is recursive or not and what wouldn't work if that setting would be changed. Any clever link where something really useful can be found? Wikipedia doesn't help me: http://en.wikipedia.org/wiki/Name_server#Recursive_query http://en.wikipedia.org/wiki/Name_server#Recursive_query Thanks in advance!
- devicenull 14y agoIt is recursive, and I honestly have no idea how to fix it. We're in a similar situation, and the only answers I can find for this involve disabling the DNS server (which would break AD). Honestly, your best bet is to firewall off UDP port 53 to all hosts except ones that are using it as a DNS server.
- acqq 14y agoIt seems my server schouldn't be a problem, it's behind the NAT and there's no port forwarding of port 53. If I would have to do the resoluion for the public nodes of my domain I'd anyway have a separate Linux or BSD node just for that, replying only the queries about my nodes. Anybody knows if I'm missing something in such a solution?