Preventing Unauthorized Zone Transfers
It’s important to ensure that only the intended name servers—usually this means the secondary name servers listed in the zone’s NS records—can transfer zones from your primary name server. Users on remote hosts that can query your name server’s zone data can look up data (for example, addresses) only for hosts whose domain names they already know, one at a time. Users who can start zone transfers from your server can list all the hosts in your zones. It’s the difference between letting random folks call your company’s switchboard and ask for John Q. Cubicle’s phone number and sending them a copy of your corporate phone directory.
You control which name servers can perform a zone transfer with settings on the Zone Transfers tab of the zone properties window (see Figure 11-4). You can allow any host to perform zone transfers, or only those name servers listed in the zone’s NS records, or only a specific set of name servers you list by IP address.
For a primary name server accessible from the Internet, you definitely want to limit zone transfers to just authorized secondary name servers. You probably don’t need to restrict zone transfers on name servers inside your firewall, unless you’re worried about your own employees listing your zone data.
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access