QUESTION POSED ON: 21 July 2003 Currently, we have the TrendMicro-NAV running in the DMZ. What are the pros and cons of enabling reverse DNS? And where can I find some supporting documentation?
>
EXPERT RESPONSE
One advantage is that some programs will allow you to refuse a connection if the reverse DNS does not match the forward DNS. It is another level of security that can be added, and can also be useful for logging purposes. You can, however, do a reverse DNS lookup using the "dnsname" command or simply by pinging the address. Most people agree that this is more of a headache than a help. There are other security means that are not such a pain. The matching between the forward and reverse DNS is set by the application to either match within a period of time or timeout. This can leave a workstation "hung" for a period of time. Further, DNS configuration errors can cause a 4 aspirin headache. You can find further information on this topic at IETF's website www.ietf.org and do a keyword search. There is also information on most of the active equipment manufacturer's sites that offer tech support or knowledge bases.
Search and Browse the Expert Answer Center Search and browse more than 25,000 question and
answer pairs from more than 250 TechTarget industry experts.
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.