Home Forums OS X Server and Client Discussion Questions and Answers question firewall and bind

Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • #355555
    Anonymous
    Participant

    hi all,

    I used the app “macanalysis” to check a new configured mac os x 10.2.4 server.

    this app found 2 minor and this “major” security hole:

    Bind:53 is active (Risk: Very High)
    Resume: This server respond to an IQUERY and NXT request, this
    vulnerability can be exploited to gain root compromise.
    Fix: Restrict access to 53/tcp to local clients and nameservers.

    unfortunately I don’t know how to close this potential security hole,
    so I would like to ask, if anybody has some advice for me – many
    thanks in advance!

    yours sincerely

    ferdinand

    #355557
    Anonymous
    Participant

    hello joel,

    unfortunately I need the dns-services. I come up with another idea:

    we have this equipment:
    cablemodem -> zyxel router with nat -> every outside traffic goes to 192.168.0.3, the ip-address of our dns-/file-/mail-server. our domain is hosted outside the network. in the lan I use the same domainname as we have outside hostet by our provider. the mx-record points to the ip-address of the zyxelrouter. everything works fine.

    my question is:
    if I activate the firewall and configure the port 53 to allow access inside the network and only the ip-adress of the nameserver of our hostingprovider from outside, will our mail-server be accessible from outside?

    I think, if somebody send me an email (e.g. [email protected]), his mail-server checks the nameserver of our hostingprovider, find the information, that mail.mydomain.com has the ipaddress x.x.x.x and sends then directly the email to our server. so if this mailserver sends the email, does he need our dns-server to reach the mailserver, or does his mailserver directly connect to our email-server?

    or to ask generally: is there a reason, why our lan-dns-server should be reachable from the outside?

    many thanks for your help in advance!

    yours sincerely

    ferdinand

Viewing 2 posts - 1 through 2 (of 2 total)
  • You must be logged in to reply to this topic.

Comments are closed