[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: (long) tcpd compilation options and forced reverse lookup



On Wed, Jun 13, 2001 at 03:04:37PM -0000, Pawel Wiecek wrote:
> On Jun 13,  3:57pm, Edouard Lafargue wrote:
> >   * Two hosts, host1 and host2 have internet connection but the DNS is down
> >   for some reason (for example mobile computers, or ppp link down etc...)
> 
> Not that is the answer to your question, but I personally prefer to have DNS
> installed on every Linux machine I have -- DNS cache is rather convenient,
> especially if either the link is slow (reduces traffic) or the DNS sometimes
> goes out.

To counter your argument, sometimes you don't want DNS at all on your 
servers. That whay there are no external dependencies that can be hijacked. 
If you are relying on domain names outside of your control, then you have 
relatively week security. Any name -> address mappings can be done 
exclusivly in /etc/hosts; resolving then becomes much quicker: either 
its locally known, or not. No need to wait for DNS to trip around the 
planet asking questions...

By installed, I mean, the server itself is using the DNS (look at 
/etc/hosts.conf: hosts, bind, or just hosts). Running a DNS server for 
other clients to use is a separate matter. Proxy, Mail, servers need DNS. 
Web servers, IMAP serevers, FTP servers, etc, do not really need it.

Oh well, just a few thoughts. Yours,
  James

-- 
 James Bromberger <james_AT_rcpt.to> www.rcpt.to/~james

       * *  C u in Bordeaux - 1st Debian Conference, July 2001 * * 
 Remainder moved to http://www.rcpt.to/~james/james/sig.html

Attachment: pgpbUEhi1iK8R.pgp
Description: PGP signature


Reply to: