Re: Same source port queries dropped by ServerIron load balancer

2010-04-04 Thread Kevin Darcy
On 4/1/2010 9:19 PM, Barry Margolin wrote: In articlemailman.1048.1270148466.21153.bind-us...@lists.isc.org, Kevin Darcyk...@chrysler.com wrote: Re-use of source ports for DNS queries is a bad security practice. I cast my vote in favor of penalizing it, in the default configuration of

Re: Same source port queries dropped by ServerIron load balancer

2010-04-04 Thread Sten Carlsen
On 04/04/10 17:41, Kevin Darcy wrote: On 4/1/2010 9:19 PM, Barry Margolin wrote: In articlemailman.1048.1270148466.21153.bind-us...@lists.isc.org, Kevin Darcyk...@chrysler.com wrote: Re-use of source ports for DNS queries is a bad security practice. I cast my vote in favor of

Re: Same source port queries dropped by ServerIron load balancer

2010-04-04 Thread Mark Andrews
In message 4bb8b33b.4070...@chrysler.com, Kevin Darcy writes: On 4/1/2010 9:19 PM, Barry Margolin wrote: In articlemailman.1048.1270148466.21153.bind-us...@lists.isc.org, Kevin Darcyk...@chrysler.com wrote: Re-use of source ports for DNS queries is a bad security practice. I