D
David Cullum
Current config:
2 domain controllers
2 DNS servers (pri & sec)
36 clients on DHCP using non-routable ip's (172.19.220.x)
web & mail running on sec dns
Problem:
Running app that requires messaging on ALL comps so dynamic updates a must.
DNS use 2 nics; one for ext & 1 for int access. Using IP filtering on
external nic for some security. Started with TCP & UDP port 53 with
protocols 6 & 17 open on external & all ports/protocols open on internal. On
forward lookup zone I lose the secondary server listing on the external zone
but internal zone still listed. DO NOT have dynamic updates checked on
either nic of either DNS server. After manually entering the IP's in the
forward lookup for the secondary DNS server, external listing dissappears
after about 2 hrs. Primary always stays there (obviously). I opened port 135
for the port mapper (which works now) but this is very dangerous. Welcome to
messages from every twit on the internet! Disabling the message service
kills those but now the app won't work properly.
Question:
Now, since port 53 is not the only port used for dynamic updates, what
port(s) is/are used? 137 (WINS)? 138 (NetBIOS datagram)? Any help from
anybody would be appreciated
2 domain controllers
2 DNS servers (pri & sec)
36 clients on DHCP using non-routable ip's (172.19.220.x)
web & mail running on sec dns
Problem:
Running app that requires messaging on ALL comps so dynamic updates a must.
DNS use 2 nics; one for ext & 1 for int access. Using IP filtering on
external nic for some security. Started with TCP & UDP port 53 with
protocols 6 & 17 open on external & all ports/protocols open on internal. On
forward lookup zone I lose the secondary server listing on the external zone
but internal zone still listed. DO NOT have dynamic updates checked on
either nic of either DNS server. After manually entering the IP's in the
forward lookup for the secondary DNS server, external listing dissappears
after about 2 hrs. Primary always stays there (obviously). I opened port 135
for the port mapper (which works now) but this is very dangerous. Welcome to
messages from every twit on the internet! Disabling the message service
kills those but now the app won't work properly.
Question:
Now, since port 53 is not the only port used for dynamic updates, what
port(s) is/are used? 137 (WINS)? 138 (NetBIOS datagram)? Any help from
anybody would be appreciated