Niall,

Thanks very much for linking me to that article. It turns out extremehosting.ca blocks incoming connections on port 53 which also originate on 53. I've disabled the outgoing source port restrictions and all is well again.

Also, securing against a cache poisoning vulnerability is a nice side effect of this problem/solution.

Thanks again!

Keith



On 22/09/11 02:02 PM, Niall O'Reilly wrote:
On 22/09/11 17:34, Keith Burgoyne wrote:
Here's the named.conf file from my name server.

        The meat of your configuration seems to be in the (hidden)
        included files.

        Forcing the source of your outgoing queries always to be
        port 53 is a well-documented bad idea.  You might find
        https://www.dns-oarc.net/oarc/services/porttest an
        interesting read.

        Best regards,
        Niall O'Reilly
_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Reply via email to