Hi
I havesetup set up two DNS servers, one acts as master and the other as slave. Without Packet Filter (PF) enabled on both machines, zone transfer from master to slave works perfectly. Enabling PF on the master only, a zone transfer works. Now my problem is enabling PF filter on both master and slave machine: zone transfers fail.
Can someone please help me out on why the zone transfer fails after enabling PF on slave?
Slave PF configuration:
Thanks
I have
- Without PF -> zone transfer works
- Enabling PF on master only -> zone transfer works
- Enabling PF on both master and slave -> zone transfer never happens (fails)
Can someone please help me out on why the zone transfer fails after enabling PF on slave?
Slave PF configuration:
Code:
if = "myif0"
master = "master_dns_ip"
clients = "{my_clients_ip/XX}" # [B]includes master_dns_ip[/B]
set skip on lo0
scrub on $if all no-df random-id min-ttl 30 max-mss 1500 fragment drop-ovl reassemble tcp
block all
antispoof quick for {lo0 $if} inet
pass in on $if inet proto {tcp, udp} from $clients to ($if) port 53 keep state
pass out on $if inet proto {tcp, udp} from ($if) to $master port 53 keep state
Thanks