Search Again:

Re: Zone Transfers

From: Global Homes Webmaster
Date: Tuesday, April 15, 2003
Time: 2:05:25 pm

On 04/15/03 at 15:41, Jessica Landmann opined:

> Hi all,
>
> New to the list and have a few questions to ask. I am running Quick
> DNS 2.2.1 and have been for a few years now. Everything works great.
>
> We recieved a request from one of our clients to restrict zone
> transfers to their mail server that is housed on a separate network,
> at their location.

Why does their mail server need to get zone transfers from you? Does the
same machine have a name server that provides slave (secondary) service for
your zones? And why would they care if you allow anyone else to get zone
transfers from your name server?

> Can we restrict zone transfers to just them?

In the Admin app, Domain->Server Preferences, 'Security' tab. You can
restrict zone transfers to hosts specified by IP address.

> We are concerned about making this change, since we have 5 web
> servers here that we don't want anything to go wrong with. The last
> thing we would like is to have something go wrong internally because
> of the switch. Thanks in advance.

It's generally a good idea to restrict zone transfers to only hosts that
are slaves (secondaries) of your master (primary) server and, possibly, any
machines on your LAN from which you might administer the master or
troubleshoot DNS problems. Any slaves, though, do need to be able to get
zone transfers. Restricting zone transfers should not affect your web
servers, as a web server should have no reason to request zone transfers.

--
Christopher Bort | cbort@globalhomes.com
Webmaster, Global Homes | webmaster@globalhomes.com
<http://www.globalhomes.com/>



Messages In This Thread:



Return to Digital Point Solutions' Home Page