What I will pursue at this point is leaving the DNS Servers recursive (we need/prefer these two dns servers for lookups for our mail servers), but restrict access to recursion via IPSec on the DNS servers. This way I can leave DNS configured as-is, but limit who can do lookups. Your opinion on this idea? I assume I can simply restrict port 52 INCOMING, to just those IP addresses I choose to allow lookups?
Is the server authoritative for any domains? If so, you probably can't block the packets at the firewall (since the firewall doesn't know which domains are yours and which are not). Otherwise, blocking incoming packets to port 53 (both UDP and TCP) from most IPs should do the trick.
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
