Re: Suspecious DNS queries dropped by Firewall

2011-12-14 Thread Kevin Oberman
On Wed, Dec 14, 2011 at 3:51 AM, babu dheen wrote: > In this case, do you think that internal users trying to send emails > directly to internet? > > Email delivery is taken care by Email Gateway device, obviously, DKIM > verification (if enabled) can only be done by Email gateway of my > company

Re: Suspecious DNS queries dropped by Firewall

2011-12-14 Thread SM
At 03:51 14-12-2011, babu dheen wrote: In this case, do you think that internal users trying to send emails directly to internet? No. Email delivery is taken care by Email Gateway device, obviously, DKIM verification (if enabled) can only be done by Email gateway of my company... How does in

Re: Suspecious DNS queries dropped by Firewall

2011-12-14 Thread Matus UHLAR - fantomas
On 14.12.11 17:21, babu dheen wrote: In this case, do you think that internal users trying to send emails directly to internet? Maybe, maybe not. DNS queries can come from many other applications. Email delivery is taken care by Email Gateway device, obviously, DKIM verification (if enabled)

Re: Suspecious DNS queries dropped by Firewall

2011-12-14 Thread G.W. Haywood
Hi there, On Wed, 14 Dec 2011 babu dheen wrote: > Can you tell me list of URL which size exceed 514 bytes to verify > whether my internal server truncate/return failure code when query > such URL using UDP query? You really ought to be able to do this for yourself. Find any domain using DNSSEC

Re: Suspecious DNS queries dropped by Firewall

2011-12-14 Thread babu dheen
the TXT record in DNS ?   Can you tell me list of URL which size exceed 514 bytes to verify whether my internal server truncate/return failure code when query such URL using UDP query?     Regards Babu --- On Tue, 13/12/11, SM wrote: From: SM Subject: Re: Suspecious DNS queries dropped by

Re: Suspecious DNS queries dropped by Firewall

2011-12-13 Thread SM
At 04:46 13-12-2011, babu dheen wrote: In what situation, DNS packet size can exceed more than 512 bytes. In fact, my gateway DNS TXT records used for DKIM, for example. Regards, -sm ___ Please visit https://lists.isc.org/mailman/listinfo/bind-us

Re: Suspecious DNS queries dropped by Firewall

2011-12-13 Thread James Michael Keller
ly not use EDNS. Overview of EDNS: https://en.wikipedia.org/wiki/Extension_mechanisms_for_DNS -James Keller --- On *Tue, 13/12/11, Anand Buddhdev //* wrote: From: Anand Buddhdev Subject: Re: Suspecious DNS queries dropped by Firewall To: "babu dheen" Cc: bind

Re: Suspecious DNS queries dropped by Firewall

2011-12-13 Thread Phil Mayers
On 13/12/11 12:46, babu dheen wrote: Dear Anand, In what situation, DNS packet size can exceed more than 512 bytes. In This has been discussed many times in the list and elsewhere. There's no need to re-iterate it again. DNS packets >512 bytes are legal. You should permit them. In this cas

Re: Suspecious DNS queries dropped by Firewall

2011-12-13 Thread babu dheen
wrote: From: Anand Buddhdev Subject: Re: Suspecious DNS queries dropped by Firewall To: "babu dheen" Cc: bind-users@lists.isc.org Date: Tuesday, 13 December, 2011, 5:39 PM On 13/12/2011 13:04, babu dheen wrote: > Hi, >  > Our company users are using internal DNS servers

Re: Suspecious DNS queries dropped by Firewall

2011-12-13 Thread Anand Buddhdev
On 13/12/2011 13:04, babu dheen wrote: > Hi, > > Our company users are using internal DNS servers for name resolution > and internal DNS servers are configured to forward the DNS query to > company gateway DNS servers for external queries > > User --> internal DNS server ---> gateway DNS server

Suspecious DNS queries dropped by Firewall

2011-12-13 Thread babu dheen
Hi,    Our company users are using internal DNS servers for name resolution and internal DNS servers are configured to forward the DNS query to company gateway DNS servers for external queries   User --> internal DNS server ---> gateway DNS server ---> internet   But when i look at the fire