Re: CARP+Pfsync+Bind

2005-10-07 Thread Vladimir Potapov
Quoting ed <[EMAIL PROTECTED]>: Zone transfers are on tcp/53, DNS lookups are 53/udp, so: pass in on $ext_if proto udp from any to $DNS port 53 keep state and if required: pass in on $ext_if proto tcp from $ext_net to $DNS port 53 keep state I use TinyDNS here, so we don't really need to tra

CARP+Pfsync+Bind

2005-10-06 Thread Vladimir Potapov
Hello everyone! We have 1 server on which running firewall and DNS master service. And we planned to install another server for load balancing and redudancy. 2 servers(each have running PF and BIND) will balancing load (or one will master and other slave) for DNS and PF. Does anyone protect DNS se