Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 12th, 2005, 11:50 PM
iceni60 iceni60 is offline
( ^o^)
 
Join Date: Jun 2004
Posts: 5,116
Default kerio DNS rules

hi, i lost my Kerio 2.1.5 rules when i did a system restore and the backup i had isn't very good. i'm trying to configure my DNS rules. i'm useing BZ's rules and he has two rules called primary and secondary DNS server. if i do ipconfg/all it shows two DNS severs they are what i am useing. do these DNS rules look OK? thanks
Attached Images
 
  #2  
Old February 13th, 2005, 12:33 AM
CrazyM's Avatar
CrazyM CrazyM is offline
Firewall Moderator
 
Join Date: Feb 2002
Location: BC, Canada
Posts: 2,433
Default Re: kerio DNS rules

Hi iceni60

Those rules look fine

Once in a blue moon DNS will use TCP outbound. If you should start to see these being blocked you could modify your rules:

Permit, Inbound, UDP, local 1024-5000, remote 53, remote IP DNS server.
Permit Outbound TCP/UDP, local 1024-5000, remote 53, remote IP DNS server.

Regards,

CrazyM
__________________
"The best thing we can do in cyberspace is exactly what we do in the real world: do our best to manage the risks."
- Bruce Schneier
  #3  
Old February 13th, 2005, 01:06 AM
iceni60 iceni60 is offline
( ^o^)
 
Join Date: Jun 2004
Posts: 5,116
Default Re: kerio DNS rules

Quote:
Originally Posted by CrazyM
Hi iceni60

Those rules look fine

Once in a blue moon DNS will use TCP outbound. If you should start to see these being blocked you could modify your rules:

Permit, Inbound, UDP, local 1024-5000, remote 53, remote IP DNS server.
Permit Outbound TCP/UDP, local 1024-5000, remote 53, remote IP DNS server.

Regards,

CrazyM
thanks, CrazyM i was going to ask about that, i would have thought it would mainly use TCP, obviously not, shows how much i know. it looks like through out the loading of a page the browser will send out a UDP DNS request, load that bit of data, then ask for the next bit, useing another DNS request, then load that, so through out the loading of a page there will be lots of little UDP datagrams. it makes sense now, i was just watching how it works with a packet sniffer. is that correct?
  #4  
Old February 13th, 2005, 09:05 PM
ghost16825 ghost16825 is offline
Regular Poster
 
Join Date: Feb 2005
Posts: 84
Default Re: kerio DNS rules

According to RFC TCP will be used for transfers over 512 bytes. It probably occurs rarer than a blue moon. I do not believe this behaviour justifies a rule but that's just me - I have never seen it occur in everyday use.

On another note, DNS bears many similarities to HTTP even though HTTP is a TCP protocol. Hence you can see why HTTP or DNS is used for covert channels.
__________________
---
Formerly the admin of the Kerio 2x-like open source project
 

Wilders Security Forums > Security Products > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:08 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums