OT: building a new MS machine and stuck at the firewall

shrek-m at gmx.de shrek-m at gmx.de
Tue Feb 28 10:52:29 GMT 2006

On 28.02.2006 04:25, Dave wrote:

> I've got two boxes, primary and secondary nameservers running bind9 
> that iptables when running does not allow zone queries and i'm getting 
> flickering timeouts.

i would accept both.
53:tcp  and  53:udp, input - destinationport  and  output - sourceport

you can check it with tcpdump, ethereal, ...

# tcpdump -nn -i eth0  udp port 53
11:31:47.354932 IP >  [...]
11:31:47.424684 IP >  [...]
# tcpdump -nn -i eth0  tcp port 53

Subject: RE: MailScanner Ports ?
From: Randal, Phil

<snip> So I stand by what I said.  For proper functioning of DNS, TCP and UDP
ports 53 are needed. </snip>

More information about the MailScanner mailing list