| |||
| [Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] |
On Thu, 24 Nov 2005 01:16:41 -0500 Dan Shoop <email@hidden> wrote:
Many things will fail without _*name resolution*_. If you have bad DNS then names are resolved improperly and things break. If you either choose not to use names, not to use DNS namespaces, or to resolve names differently this is all perfectly acceptable too. It's not that you /must/ have DNS, it's just if you /do/ have DNS it /must/ be right.
DNS is just *a* way to resolve names.
You may find this hard to believe but DNS is a very recent protocol, and the Internet ran fine for eons without it. You might not remember it, but to me it's still a relative newcomer, like HTTP.
And regardless, NAT is a level 2/3 mapping and cares not one bit about DNS. It doesn't use it, need it or care about it. Not one bit. It's all IP addresses, no names are involved to protect the guilty. It says some IP address get's remapped to some other IP address, nothing more. NAPT says that some IP-address:port gets mapped to some other IP-address:port, still no names their either. NAT does not need DNS. Period.
But you still haven't answered my biggest question: if blocking port 53 is just a bandaid for preventing DNS leakage of our private zones, what else should we be doing?
Properly configuring BIND in the first place. If you want to control who get's to resolve what how and viewed which way BIND is the place to do this, not a nasty hack at the border to make up for not doing the right thing to begin with.
| References: | |
| >Re: Another DNS question... (From: Dave Pooser <email@hidden>) | |
| >Re: Another DNS question... (From: Bret Alan <email@hidden>) | |
| >Re: Another DNS question... (From: Dan Shoop <email@hidden>) | |
| >Re: Another DNS question... (From: "Brendan O'Toole" <email@hidden>) | |
| >Re: Another DNS question... (From: Dan Shoop <email@hidden>) | |
| >Re: Another DNS question... (From: Bret Alan <email@hidden>) | |
| >Re: Another DNS question... (From: Dan Shoop <email@hidden>) | |
| >Re: Another DNS question... (From: Bret Alan <email@hidden>) | |
| >Re: Another DNS question... (From: Dan Shoop <email@hidden>) |
| Home | Archives | FAQ | Terms/Conditions | Contact | RSS | Lists | About |
Visit the Apple Store online or at retail locations.
1-800-MY-APPLE
Contact Apple | Terms of Use | Privacy Policy
Copyright © 2007 Apple Inc. All rights reserved.