Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

DNS Zone Transfer across a Firewall

Is it true that if Primary and Secondary DNS servers are either sides of PIX and PIX is using NAT the ZONE transfer will fail if the file is too long?

Thanx

Vikas Khanduri

1 REPLY
Cisco Employee

Re: DNS Zone Transfer across a Firewall

Haven't heard of any issues with that.

You may be referring to the fact the PIX will drop UDP DNS packets that are larger than 512 bytes. This keeps us in spec with RFC 1035 and prevents buffer overflow attacks to internal DNS servers.

Zone transfers, on the other hand, are TCP DNS packets and are not subject to this limitation.

446
Views
0
Helpful
1
Replies
CreatePlease to create content