[NTLUG:Discuss] opinions on where to run DNS server..... firewallvs main server.

Jonathan Miller betaray at kludge.org
Wed Mar 1 11:20:15 CST 2000


On Wed, 1 Mar 2000, MadHat wrote:

> I am curious why you say this?  How is policing UDP any differant from
> TCP, it is still based on IP and port, so why is it more dificult?  

OK, you know, I don't remember either. I saw Rusty talk about this and I
remember there was some huge problem with DNS and it's usage of TCP and
and UDP, but I might be confusing this with the problems FTP has with
ipchains. I've looked around and there doesn't seem to any problem in only
allowing access from certain machines. 

> And I don't understand the comment about the masq'ing, why would
> someone be SOL, what do you mean?  (yes, I know what SOL is, I just
> don't understand why you say that).

Well just being that if you're trying to masq a server that the real world
is going to interact with it's going to be a pain. It's easy enough if you
plan on just using it for clients on the inside of masq'ing box.





More information about the Discuss mailing list