Date: Wed, 24 May 2000 23:25:15 -0700 (PDT) From: "Rodney W. Grimes" <freebsd@gndrsh.dnsmgr.net> To: klaus@compt.com (Klaus Steden) Cc: freebsd-security@FreeBSD.ORG Subject: Re: named, and socket bindings Message-ID: <200005250625.XAA68670@gndrsh.dnsmgr.net> In-Reply-To: <20000525005653.X6137@cthulu.compt.com> from Klaus Steden at "May 25, 2000 00:56:53 am"
next in thread | previous in thread | raw e-mail | index | archive | help
The newer version of bind does not have to use port 53 for outbound queries, so it opens a high port for this. You can turn this off with options { query-source address * port 53; }; You can even force it to always use a specific IP address, which is great for named running behind firewalls/filter routers. > I was playing a bit with 'sockstat' on the FreeBSD 3.4 boxen we have around > here that offer name service. > > On both I noticed something that was, to me, a bit odd. The sockets that named > had bound were, as expected, the domain port on all the machine's interfaces, > but also, a random high UDP port. > > I checked two BSDI boxes (4.0) and they don't seem to have the same situation. > What gives? > > Did I miss or forget something obvious? Why would named have to grab a port > that's not port 53, unless it was doing a zone transfer (and that doesn't seem > to be the case) ... is this a bit of a labour-saving measure, the FreeBSD named > pre-allocates a port and uses it for zone transfers the lifetime of the whole > named process? > > I'm curious. > > Anyone have the answer? > > thanks, > Klaus > > -- > Klaus Steden | > Unix Systems Administrator | > Command Post Toybox | TODO: > http://www.compt.com/ | 1) Learn to use my new Unix account. > klaus@compt.com | 2) Learn how to change this list. > Phone: (416) 585-9995 x345 | > Fax: (416) 979-0428 | > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-security" in the body of the message > -- Rod Grimes - KD7CAX @ CN85sl - (RWG25) rgrimes@gndrsh.dnsmgr.net To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200005250625.XAA68670>