View Single Post
  #2 (permalink)  
Old 2006-10-04
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 212
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: Blocking Dynamic DNS update attempts via FW-1 custom INSPECT

Nice work - that's very helpful indeed.

Along those lines though, I would add that in light of the numerous malicious tools hiding their evil payload on port 53 as well as other problems related to DNS-reply amplification attacks, it's a good idea to consider having an internal caching server that is the only host allowed to access the Internet for DNS. This reduces queries over the firewall and can lead to a more secure policy. It's also easier to control other DNS related things as a result.
Reply With Quote