1 |
On Saturday 21 June 2008, James wrote: |
2 |
> Hello, |
3 |
> |
4 |
> I'm adding primary and secondary name servers to my small (5 |
5 |
> static) ip network. |
6 |
> |
7 |
> |
8 |
> Are there any security reasons that I should not run the secondary |
9 |
> (Bind) name server on the firewall (iptables) directly? |
10 |
|
11 |
Well, security holes have been discovered in bind in the past - and |
12 |
there are no reasons to assume none will be found in the future. ;-) |
13 |
Once your firewall is compromised, your whole network is under |
14 |
threat. |
15 |
|
16 |
Though the risk is probably small, you can avoid it easily. Rund bind |
17 |
on one of the boxes behind your firewall. Forward port 53 from your |
18 |
fw to that box. Announce your FW as the secondary name server. |
19 |
|
20 |
Uwe |
21 |
|
22 |
-- |
23 |
Ignorance killed the cat, sir, curiosity was framed! |
24 |
-- |
25 |
gentoo-user@l.g.o mailing list |