1 |
Uwe Thiem <uwix <at> iway.na> writes: |
2 |
|
3 |
> |
4 |
Are there any security reasons that I should not run the secondary (Bind) name |
5 |
server on the firewall (iptables) directly? |
6 |
|
7 |
> Well, security holes have been discovered in bind in the past - and |
8 |
> there are no reasons to assume none will be found in the future. |
9 |
> Once your firewall is compromised, your whole network is under |
10 |
|
11 |
> Though the risk is probably small, you can avoid it easily. Rund bind |
12 |
> on one of the boxes behind your firewall. Forward port 53 from your |
13 |
> fw to that box. Announce your FW as the secondary name server. |
14 |
|
15 |
|
16 |
Yep. |
17 |
That's what I was thinking too. |
18 |
|
19 |
thanks for confirming what I was leaning towards. |
20 |
|
21 |
|
22 |
James |
23 |
|
24 |
|
25 |
|
26 |
|
27 |
|
28 |
-- |
29 |
gentoo-user@l.g.o mailing list |