DNS cache poisoning vs. NAT
Sunday, 27th of July 2008The latest DNS security issue (please read Hubert’s Blog entry) proves again that NAT is a bad idea. If you run a DNS server behind a NAT (which you really shouldn’t) you can pick one of two evils: You use a fixed query source port on your DNS server which makes it susceptible to DNS [...]