Built-in recursive DNS resolver in 5.4 - ORF Forums

Built-in recursive DNS resolver in 5.4 RSS Back to forum

1

I am currently on 5.1 and will be upgrading soon to 5.4. We limit DNS queries with firewall rules to enforce using OpenDNS for content filtering. What type of firewall rule would I need to use this feature?

by mike.galbicka 7 years ago
2

@mike.galbicka: Hello Mike,

If you want to use the built-in DNS resolver you have to open the ports UDP/53 and TCP/53 to any internet hosts, as ORF will perform the DNS lookups recursively on its own - without the help of any external DNS server.

However, if you want to keep using an external DNS resolver and/or you cannot allow DNS traffic to any hosts (i.e. you must restrict the DNS ports to a specific nameserver), you should keep using ORF with your current settings - with the "external DNS server" option enabled: http://vamsoft.com/support/docs/orf-help/5.4/adm-dns-settings

by Daniel Novak (Vamsoft) 7 years ago
(in reply to this post)

3

@Daniel Novak (Vamsoft): Then this rule would work I assume.
Orf Server IP Address -> Any External IP Address Allow UDP/TCP port 53

by mike.galbicka 7 years ago
(in reply to this post)

4

@mike.galbicka: Yes, an outbound rule such as the one you described above should work just fine.

by Daniel Novak (Vamsoft) 7 years ago
(in reply to this post)

5

@Daniel Novak (Vamsoft): I created and enabled the firewall rule then did the upgrade and enabled the built in recursive DNS resolver and all is well.

by mike.galbicka 7 years ago
(in reply to this post)

6

@mike.galbicka: Thank you for the update. I am glad to hear everything is working well.

by Daniel Novak (Vamsoft) 7 years ago
(in reply to this post)

7

Actually after monitoring for a few days I am noticing the DNS timeout counter is running much higher then before. It is currently set with a 12 second timeout. I also notice that DNS caching is not available with the recursive resolver.

by mike.galbicka 7 years ago
8

@mike.galbicka: Hello mike,

That is correct, ORF's built-in recursive resolver has its own caching mechanism, thus you cannot share the cached DNS data with other servers (see the related ORF help topic: https://vamsoft.com/support/docs/orf-help/5.4/adm-dns). Furthermore, the built-in resolver depends on the available system resources of the underlying computer, thus it can become resource starved if the server gets overloaded.

by Daniel Novak (Vamsoft) 7 years ago
(in reply to this post)

New comment

Fill in the form below to add a new comment. All fields are required. If you are a registered user on our site, please sign in first.

It will not be published.
hnp1 | hnp2