cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
501
Views
0
Helpful
4
Replies

configuring DNS on firewall

Bruce Summers
Level 1
Level 1

is it necessary to allow both UDP and TCP port 53 for accessing DNS servers through a firewall access-list?

1 Accepted Solution

Accepted Solutions

tcp/53 is used for zone-transfers. if you are doing just normal queries udp/53 will suffice.

View solution in original post

4 Replies 4

tcp/53 is used for zone-transfers. if you are doing just normal queries udp/53 will suffice.

thanks vikram.

Here is another reason why tcp/53 is used "A client can use TCP whenever it wants, and has to use TCP when the response it gets via UDP is truncated because it is too long"

tcp/53 is also used for large transfers.

Review Cisco Networking products for a $25 gift card