cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
499
Views
0
Helpful
4
Replies

configuring DNS on firewall

Bruce Summers
Level 1
Level 1

is it necessary to allow both UDP and TCP port 53 for accessing DNS servers through a firewall access-list?

1 Accepted Solution

Accepted Solutions

tcp/53 is used for zone-transfers. if you are doing just normal queries udp/53 will suffice.

View solution in original post

4 Replies 4

tcp/53 is used for zone-transfers. if you are doing just normal queries udp/53 will suffice.

thanks vikram.

Here is another reason why tcp/53 is used "A client can use TCP whenever it wants, and has to use TCP when the response it gets via UDP is truncated because it is too long"

tcp/53 is also used for large transfers.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card