port filtering

B

Brent Peterson

I am looking for port information to filter between two Microsoft DNS
servers

I have port 53 UDP/TCP open but I can not transfer to the secondary servers
unless I turn off port filtering.

What other ports do I need open?

Brent
 
W

William Stacey

That should do it. What filter are you using and how did you setup the
rules?
Use IP addresses in the example.
 
K

Kevin D. Goodknecht Sr. [MVP]

In
Brent Peterson said:
I am looking for port information to filter between two Microsoft DNS
servers

I have port 53 UDP/TCP open but I can not transfer to the secondary
servers unless I turn off port filtering.

What other ports do I need open?

Brent

If you are attempting to use port filtering on the interface you need to
open ports for outbound connections. So what you are going to have to do is
open ports starting at 2400 to 65535.
It is much easier to use the port filtering in RRAS, while RRAS does not
allow you to open port ranges you can open the incoming ports you need then
allow all established connections coming from your internal network.
Firewalls such as Zone Alarm from Zone Labs are a lot easier to configure
for these connections and can distinguish between the authorised programs
using these ports so it won't allow unauthorised programs such as Worms and
Trojans to use these ports.
I am not pushing any type or brand of firewalls I am just trying to make you
aware of the reprocutions of systematically opening or closing ports.
For information on configuring RRAS port filtering aka "The Poor Mans
Firewall" can be found here: 254018 - How to Configure Input Filters for
Services That Run Behind Network Address Translation
http://support.microsoft.com/default.aspx?scid=kb;en-us;254018
 
D

DJ

Consider using protocol capture between two servers
It could help you troubleshoot the problem ...
 
K

Kevin D. Goodknecht Sr. [MVP]

In
William Stacey said:
I get UDP source ports in the 1034/1035 also for outbound queries
from the DNS server.

That's the number I was looking for thanks William. Should be 1034-65535.
 
A

Ace Fekay [MVP]

In
posted their urgent concerns said:
I am looking for port information to filter between two Microsoft DNS
servers

I have port 53 UDP/TCP open but I can not transfer to the secondary
servers unless I turn off port filtering.

What other ports do I need open?

Brent

Unfortunately, MS DNS needs that wide range opened that William and Kevin
mentioned.

--
Regards,
Ace

Please direct all replies to the newsgroup so all can benefit.

Ace Fekay, MCSE 2000, MCSE+I, MCSA, MCT, MVP
Microsoft Windows MVP - Active Directory
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top