[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

DNS Client port range

Posted on 2006-06-25
3
Medium Priority
?
387 Views
Last Modified: 2013-12-04
Hi,

I wish to implement ip filtering on all my client PCs but I'm having problems with my Win2k3 dns server as the client-side port range is massive. To quote MS:

"By default, Windows Server 2003 and Windows 2000 Server DNS servers use ephemeral client-side ports when they query other DNS servers...."

Is there any proper way to reduce the port range on the dns server to a manageable number? Is there a way it can be reduced to a single port? Is there a performance issue with implementing this?

Also, under what conditions does a dns client and server choose to use udp over tcp? Is there any way of choosing just one protocol? Which one is better?

Thanks
0
Comment
Question by:gibjon
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 12

Accepted Solution

by:
gidds99 earned 2000 total points
ID: 16982632
Windows uses ephemiral ports for DNS connections as you have mentioned above.  These ports fall within the range 1024 to 5000.  You can control this range via a registry setting but it is not only limited to DNS connections (it affects all connections). Clearly if the range was limited too much this may cause problems.

Hope this helps.
0

Featured Post

Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This is a guide to the following problem (not exclusive but here) on Windows: Users need our support and we supporters often use global administrative accounts to do this. Using these accounts safely is a real challenge. Any admin who takes se…
Security measures require Windows be logged in using Standard User login (not Administrator).  Yet, sometimes an application has to be run “As Administrator” from a Standard User login.  This paper describes how to create a shortcut icon to launch a…
In this video, Percona Solution Engineer Rick Golba discuss how (and why) you implement high availability in a database environment. To discuss how Percona Consulting can help with your design and architecture needs for your database and infrastr…
Want to learn how to record your desktop screen without having to use an outside camera. Click on this video and learn how to use the cool google extension called "Screencastify"! Step 1: Open a new google tab Step 2: Go to the left hand upper corn…
Suggested Courses

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question