RE: DNS Zone XFers

  • From: "Thomas W Shinder" <tshinder@xxxxxxxxxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Thu, 23 Oct 2003 15:34:02 -0500

Hi Glenn,
 
If the service is running on the fireall, then packet filters for the
required protocol are required :-)
 
TCP 53 inbound from all ports.
 
HTH<
Tom
 
 
Thomas W Shinder
www.isaserver.org/shinder <http://www.isaserver.org/shinder>  
ISA Server and Beyond: http://tinyurl.com/1jq1
Configuring ISA Server: http://tinyurl.com/1llp
<http://tinyurl.com/1llp> 

 

        -----Original Message-----
        From: Glenn Maks [mailto:gmaks@xxxxxxxxx] 
        Sent: Thursday, October 23, 2003 2:41 PM
        To: [ISAserver.org Discussion List]
        Subject: [isalist] RE: DNS Zone XFers
        
        
        http://www.ISAserver.org
        
        Ok - did that and the same results, was unable to xfer zone, in
addition, I was no longer able to do NSLOOKUPs so I re-enabled the DNS
Filter ... The DNS Filter definition is for DNS lookups, do I have to
create special packet filters and apply them to the Public interface of
ISA to get a successful Zone XFer ?

                -----Original Message-----
                From: Thomas W Shinder
[mailto:tshinder@xxxxxxxxxxxxxxxxxx]
                Sent: Thursday, October 23, 2003 3:07 PM
                To: [ISAserver.org Discussion List]
                Subject: [isalist] RE: DNS Zone XFers
                
                
                http://www.ISAserver.org
                
                Hi Glenn,
                 
                Disable the DNS filter and try it again.
                 
                HTH,
                Tom
                 
                 
                Thomas W Shinder
                www.isaserver.org/shinder
<http://www.isaserver.org/shinder>  
                ISA Server and Beyond: http://tinyurl.com/1jq1
                Configuring ISA Server: http://tinyurl.com/1llp
<http://tinyurl.com/1llp> 
                
                 

                        -----Original Message-----
                        From: Glenn Maks [mailto:gmaks@xxxxxxxxx] 
                        Sent: Thursday, October 23, 2003 2:01 PM
                        To: [ISAserver.org Discussion List]
                        Subject: [isalist] DNS Zone XFers
                        Importance: High
                        
                        
                        http://www.ISAserver.org
                        

                        To allow DNS Zone XFers onto a Microsoft ISA
Server, does one have to create Protocol Rules that include the
pre-defined DNS protocols? I get a 6523 error when I try to create a
secondary zone file and transfer it from my primary DNS Server ???


                          Thank U 
                            Glenn 

        
------------------------------------------------------
                        List Archives:
http://www.webelists.com/cgi/lyris.pl?enter=isalist
                        ISA Server Newsletter:
http://www.isaserver.org/pages/newsletter.asp
                        ISA Server FAQ:
http://www.isaserver.org/pages/larticle.asp?type=FAQ
        
------------------------------------------------------
                        Other Internet Software Marketing Sites:
                        Leading Network Software Directory:
http://www.serverfiles.com
                        No.1 Exchange Server Resource Site:
http://www.msexchange.org
                        Windows Security Resource Site:
http://www.windowsecurity.com/
                        Network Security Library: http://www.secinf.net/
                        Windows 2000/NT Fax Solutions:
http://www.ntfaxfaq.com
        
------------------------------------------------------
                        You are currently subscribed to this
ISAserver.org Discussion List as: tshinder@xxxxxxxxxxxxxxxxxx
                        To unsubscribe send a blank email to
$subst('Email.Unsub') 

                ------------------------------------------------------
                List Archives:
http://www.webelists.com/cgi/lyris.pl?enter=isalist
                ISA Server Newsletter:
http://www.isaserver.org/pages/newsletter.asp
                ISA Server FAQ:
http://www.isaserver.org/pages/larticle.asp?type=FAQ
                ------------------------------------------------------
                Other Internet Software Marketing Sites:
                Leading Network Software Directory:
http://www.serverfiles.com
                No.1 Exchange Server Resource Site:
http://www.msexchange.org
                Windows Security Resource Site:
http://www.windowsecurity.com/
                Network Security Library: http://www.secinf.net/
                Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
                ------------------------------------------------------
                You are currently subscribed to this ISAserver.org
Discussion List as: gmaks@xxxxxxxxx
                To unsubscribe send a blank email to
$subst('Email.Unsub') 

        ------------------------------------------------------
        List Archives:
http://www.webelists.com/cgi/lyris.pl?enter=isalist
        ISA Server Newsletter:
http://www.isaserver.org/pages/newsletter.asp
        ISA Server FAQ:
http://www.isaserver.org/pages/larticle.asp?type=FAQ
        ------------------------------------------------------
        Other Internet Software Marketing Sites:
        Leading Network Software Directory: http://www.serverfiles.com
        No.1 Exchange Server Resource Site: http://www.msexchange.org
        Windows Security Resource Site: http://www.windowsecurity.com/
        Network Security Library: http://www.secinf.net/
        Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
        ------------------------------------------------------
        You are currently subscribed to this ISAserver.org Discussion
List as: tshinder@xxxxxxxxxxxxxxxxxx
        To unsubscribe send a blank email to
$subst('Email.Unsub') 

Other related posts: