Gentoo Archives: gentoo-user

From: James <wireless@×××××××××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: firewall + dns secondary
Date: Mon, 23 Jun 2008 00:51:39
Message-Id: loom.20080623T004815-813@post.gmane.org
In Reply to: Re: [gentoo-user] firewall + dns secondary by Uwe Thiem
1 Uwe Thiem <uwix <at> iway.na> writes:
2
3 >
4 Are there any security reasons that I should not run the secondary (Bind) name
5 server on the firewall (iptables) directly?
6
7 > Well, security holes have been discovered in bind in the past - and
8 > there are no reasons to assume none will be found in the future.
9 > Once your firewall is compromised, your whole network is under
10
11 > Though the risk is probably small, you can avoid it easily. Rund bind
12 > on one of the boxes behind your firewall. Forward port 53 from your
13 > fw to that box. Announce your FW as the secondary name server.
14
15
16 Yep.
17 That's what I was thinking too.
18
19 thanks for confirming what I was leaning towards.
20
21
22 James
23
24
25
26
27
28 --
29 gentoo-user@l.g.o mailing list