North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: DNS deluge for

  • From: Chris Adams
  • Date: Fri Feb 24 19:59:21 2006

Once upon a time, Rob Thomas <[email protected]> said:
> Limit recursion to trusted netblocks and customers.  Do not permit
> your name servers to provide recursion for the world.  If you do,
> you will contribute to one of these attacks.

One thing to note: we've discovered that on some common DSL routers, the
internal DNS caching server is on by default and answers requests on the
outside IP address.  IIRC some even do it when configured for NAT.

So, even when you disable outside recursion, things you may not think of
on the inside of your network may still allow outside DNS recursion.

Chris Adams <[email protected]>
Systems and Network Administrator - HiWAAY Internet Services
I don't speak for anybody but myself - that's enough trouble.