[ previous ] [ next ] [ threads ]
 From:  Michael Sierchio <kudzu at tenebras dot com>
 To:  m0n0wall at lists dot m0n0 dot ch
 Subject:  Re: [m0n0wall] Are TCP DNS queries possible?
 Date:  Tue, 13 Sep 2005 12:04:30 -0700
Robert Goodyear wrote:

> I need m0n0 to respond to TCP DNS queries. Does anyone know if this  is 
> possible or if there's a workaround to permit this functionality?

Why?  Zone transfers?  In all other cases, a DNS server should respond
with a RST-ACK to queries on 53/TCP unless the state of things indicates
that a 53/UDP query failed due to payload being greater than 512 bytes.

And *that* condition is a sign of something seriously broken, IMHO.

If your records are properly configured, you'll never have need to
respond to TCP queries.

What are you trying to do?