<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>DNS checker reboots ZyWALL in ZyXEL</title>
<link>http://www.dslreports.com/forum/r20767898</link>
<description></description>
<language>en</language>
<pubDate>Wed, 03 Dec 2008 03:00:19 EDT</pubDate>
<lastBuildDate>Wed, 03 Dec 2008 03:00:19 EDT</lastBuildDate>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20952300</link>
<description><![CDATA[<A HREF="/useremail/u/391339"><b>CampMaster</b></A> : <div class="bquote"><small>said by  Brano <A HREF="/useremail/u/649954"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Which version do you have?<br>I've got V4.04(XD.1)_db(0808) | 08/08/2008<br> </div>Ahhh, I have:  V4.04(XD.1)_db(0714) | 07/15/2008<br><br>~CMT<br><small>--<br>There's no place like 127.0.0.1<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20952300</guid>
<pubDate>Thu, 14 Aug 2008 19:25:42 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20952290</link>
<description><![CDATA[<A HREF="/useremail/u/649954"><b>Brano</b></A> : Which version do you have?<br>I've got V4.04(XD.1)_db(0808) | 08/08/2008]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20952290</guid>
<pubDate>Thu, 14 Aug 2008 19:23:28 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20951837</link>
<description><![CDATA[<A HREF="/useremail/u/391339"><b>CampMaster</b></A> : I received the Beta FW for the ZW5.<br><br>I have a DNS Server behind the ZW5.<br><br>Sadly, the beta firmware does NOT randomize source ports:<br>Number of samples: &#9;23<br>Unique ports: &#9;23<br>Range: &#9;15043 - 15159<br>Modified Standard Deviation: &#9;22<br>Bits of Randomness: &#9;6<br>Values Seen: &#9;15138 15139 15140 15141 15142 15143 15144 15145 15043 15146 15147 15148 15149 15150 15151 15152 15153 15154 15155 15156 15157 15158 15159<br><br>~CMT<br><small>--<br>There's no place like 127.0.0.1<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20951837</guid>
<pubDate>Thu, 14 Aug 2008 17:47:55 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20948140</link>
<description><![CDATA[<A HREF="/useremail/u/649954"><b>Brano</b></A> : This was just test to my ISP's DNS servers.<br>ZyXel is fully aware of all the issues and the new FW should be out within a month. I'm sure we'll give it a close look then ;) (I don't have much spare time now to check this beta release thoroughly).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20948140</guid>
<pubDate>Thu, 14 Aug 2008 00:06:11 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20947788</link>
<description><![CDATA[<A HREF="/useremail/u/782487"><b>jamesv</b></A> : brano, were those results using queries sourced by the Z5's internal nameserver or one on a separate server behind the NAT on the LAN?<br><br>ZyXel has two separate issues: fixing the DNS cache within the ZyWall and fixing the NAT within the ZyWall so that it does not linearize random source ports on a LAN server.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20947788</guid>
<pubDate>Wed, 13 Aug 2008 22:48:55 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20917559</link>
<description><![CDATA[<A HREF="/useremail/u/649954"><b>Brano</b></A> : Here are tests with the Z5 beta firmware.<br>I'll do some sniffing to check source ports tomorrow.<br><br>[att=1]<br>Test from &raquo;<A HREF="http://www.doxpara.com" >www.doxpara.com</A><br><br>[att=2]<br>Test from &raquo;<A HREF="http://entropy.dns-oarc.net/test" >entropy.dns-oarc.net/test</A><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/20917559?c=1336182&ret=L2ZvcnVtL3IyMDc2Nzg5OC54bWw%3D"><IMG TITLE="6967 bytes" BORDER=0 WIDTH=248 HEIGHT=235 SRC="/r0/download/1336182~dc4d89861da876a3fb8154d45d96f0b1/Untitled-2.png"></A></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20917559?c=1336183&ret=L2ZvcnVtL3IyMDc2Nzg5OC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="51548 bytes" WIDTH=600 HEIGHT=753 SRC="/r0/download/1336183.thumb600~19a6a9085bc66dde26a8720afef6f892/Untitled-1.png/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20917559</guid>
<pubDate>Fri, 08 Aug 2008 00:28:49 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20911921</link>
<description><![CDATA[<A HREF="/useremail/u/391339"><b>CampMaster</b></A> : Will that update also provide for the randomizing of outgoing ports?<br><br>When is this expected to be released? for the ZW5?<br><br>Thanks!<br><br>~CMT<br><small>--<br>There's no place like 127.0.0.1<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20911921</guid>
<pubDate>Thu, 07 Aug 2008 00:34:39 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20852578</link>
<description><![CDATA[<A HREF="/useremail/u/649954"><b>Brano</b></A> : The DNS checker reboot issue has been fixed in current beta firmware. Should be in next formal release.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20852578</guid>
<pubDate>Sat, 26 Jul 2008 13:54:09 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20840265</link>
<description><![CDATA[<A HREF="/useremail/u/226051"><b>bbarrera</b></A> : My understanding is that ZLD-based ZyWALLs (zw1050 and USG) firewalls have a NAT implementation that does not change source ports unless the port is currently in use and then it uses a random port above port 1025.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20840265</guid>
<pubDate>Thu, 24 Jul 2008 02:18:28 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20831985</link>
<description><![CDATA[<A HREF="/useremail/u/226051"><b>bbarrera</b></A> : The ZyWALL 1050 and USG300 appear to be randomizing ports for the LAN-based recursive dns caches. The ZyWALL 1050 has Windows Server 2000 on its LAN and USG300 has djbnds on its LAN.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20831985</guid>
<pubDate>Tue, 22 Jul 2008 16:16:09 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20827669</link>
<description><![CDATA[<A HREF="/useremail/u/226051"><b>bbarrera</b></A> : I understand that on the Linux-based zw1050/USG devices they are using BIND for dns proxy cache and the transaction IDs were fixed last year. They are now working on source port randomization.<br><br>Separately I asked about NAT port randomization and haven't received a reply yet, although I haven't tested to see if it is a problem.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20827669</guid>
<pubDate>Mon, 21 Jul 2008 20:27:46 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20827413</link>
<description><![CDATA[<A HREF="/useremail/u/1161423"><b>dslpartner</b></A> : <div class="bquote"><small>said by  OZO <A HREF="/useremail/u/755055"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I suppose fix will be in the next firmware release.<br> </div>Based on what?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20827413</guid>
<pubDate>Mon, 21 Jul 2008 19:35:40 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20827282</link>
<description><![CDATA[<A HREF="/useremail/u/782487"><b>jamesv</b></A> : Well, after a little more thought I realized the writeup I got isn't it either - that can be addressed in code on the cache (percentages made very low).  So it's something else...<br><br>But predictable port numbers doesn't seem like a good idea for a firewall on general principles, and a "short-circuit" in the NAT port remapper to use the LAN source port if free on the WAN side seems unlikely to take long to implement or test and has a low chance of breakage.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20827282</guid>
<pubDate>Mon, 21 Jul 2008 19:09:02 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20827161</link>
<description><![CDATA[<A HREF="/useremail/u/755055"><b>OZO</b></A> : I suppose fix will be in the next firmware release.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20827161</guid>
<pubDate>Mon, 21 Jul 2008 18:49:02 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20826830</link>
<description><![CDATA[<A HREF="/useremail/u/1161423"><b>dslpartner</b></A> : Anybody tried to tell ZyXEL about this, if yes, what was the answer?<br><small>--<br>"Perl is executable line noise, Python is executable pseudo-code."</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20826830</guid>
<pubDate>Mon, 21 Jul 2008 17:47:08 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20826637</link>
<description><![CDATA[<A HREF="/useremail/u/782487"><b>jamesv</b></A> : <div class="bquote"><small>said by  bbarrera <A HREF="/useremail/u/226051"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>DNS protocol was not designed to be secure but that doesn't excuse BIND from ignoring for many years a well known implementation technique that would reduce chance for cache poisoning. <br> </div>I've now read a writeup of the problem and it has nothing to do with the coding, bind, or such.<br><br>But even with the bind or djbdns fixes it isn't safe to have a DNS cache behind a ZyWall until ZyXel fixes the NAT - ZyXel undoes the DNS fixes and leaves a cache as unsafe as if it had never been patched in the first place.<br><br>(the writeup I saw required that the attacker be able to send queries to the cache, which can be blocked.  But I think it is also possible to get those queries made by poisoning a web site so that a browser on the "inside" does the queries to the cache which will be attacked - just blocking incoming DNS queries isn't good enough).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20826637</guid>
<pubDate>Mon, 21 Jul 2008 17:15:18 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20823062</link>
<description><![CDATA[<A HREF="/useremail/u/226051"><b>bbarrera</b></A> : DNS protocol was not designed to be secure but that doesn't excuse BIND from ignoring for many years a well known implementation technique that would reduce chance for cache poisoning. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20823062</guid>
<pubDate>Sun, 20 Jul 2008 23:56:15 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20820053</link>
<description><![CDATA[<A HREF="/useremail/u/782487"><b>jamesv</b></A> : <div class="bquote"><small>said by  bbarrera <A HREF="/useremail/u/226051"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Unlike BIND and Microsoft DNS the djbdns dns cache has *never* been vulnerable to this exploit, and is credited with identifying the dns system design flaw and fix many years ago.<br> </div>ISC and others seem to believe the problem is in the protocol not any particular cache software.  ISC believes no software change is a complete fix but instead just makes the attack harder and that DNSSEC is the only complete solution.<br><br>If you're running djbdns behind a ZyWall whose NAT is remapping ports then the ZyWall may be undoing some of djbdns' security by making the DNS query ports predictable.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20820053</guid>
<pubDate>Sun, 20 Jul 2008 11:24:23 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20815294</link>
<description><![CDATA[<A HREF="/useremail/u/279131"><b>jig</b></A> : this is interesting.<br><br>there was once a time when i was getting some issue with my z5 rebooting randomly, and i thought it had something to do with resolving lots of ips at once. couldn't ever nail it down.<br><small>--<br>Catapultam habeo. Nisi pecuniam omnem mihi dabis, ad caput tuum saxum immane mittam.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20815294</guid>
<pubDate>Sat, 19 Jul 2008 04:08:58 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20807522</link>
<description><![CDATA[<A HREF="/useremail/u/755055"><b>OZO</b></A> : I've just tested the new FW version <tt>V4.04(XD.1) | 06/26/2008</tt> and the result is the same - ZyWALL router crashes and reboots after receiving 4 UDP packets of DNS requests from my computer. :(<br><small>--<br>Keep it simple, it'll become complex by itself...</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20807522</guid>
<pubDate>Thu, 17 Jul 2008 17:00:57 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20801184</link>
<description><![CDATA[<A HREF="/useremail/u/226051"><b>bbarrera</b></A> : USG series is Unix/Linux based ("ZLD") and uses BIND.<br><br>The zw5/35/70 series use the proprietary Zyxel ZyNOS operating system and unknown DNS proxy implementation (likely proprietary).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20801184</guid>
<pubDate>Wed, 16 Jul 2008 15:35:34 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20801181</link>
<description><![CDATA[<A HREF="/useremail/u/1161423"><b>dslpartner</b></A> : <div class="bquote"><small>said by  OZO <A HREF="/useremail/u/755055"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>What firmware version does it have?<br>This info could be interesting for further investigation.<br> </div>Its not even the same os, USG uses ZLD which is Linux based and older ZyWALL uses ZyNOS which is based on something else.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20801181</guid>
<pubDate>Wed, 16 Jul 2008 15:35:01 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20801167</link>
<description><![CDATA[<A HREF="/useremail/u/755055"><b>OZO</b></A> : What firmware version does it have?<br>This info could be interesting for further investigation.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20801167</guid>
<pubDate>Wed, 16 Jul 2008 15:32:47 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20799621</link>
<description><![CDATA[<A HREF="/useremail/u/226051"><b>bbarrera</b></A> : I've setup my USG300 as DNS proxy for one LAN computer, then pointed computer's browser at the DNS checker and it didn't reboot the USG300.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20799621</guid>
<pubDate>Wed, 16 Jul 2008 10:54:59 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20798605</link>
<description><![CDATA[<A HREF="/useremail/u/755055"><b>OZO</b></A> : Thank you for checking.<br><br>I found that using ZW as a local DNS server (actually a proxy, but somehow advanced) is beneficial because:<br>1) I turn off NetBIOS on all local computers and run network without this old chatty protocol;<br>2) instead of maintaining hosts files on all computers I use ZW to keep all name resolutions for the LAN.<br><br>It's easy to add local host names and their corresponding IPs via <i>Advanced | DNS | System | Address Record</i> assignments. Try it and you won't need to change hosts files on all computers anymore.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20798605</guid>
<pubDate>Wed, 16 Jul 2008 04:11:36 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20798276</link>
<description><![CDATA[<A HREF="/useremail/u/1512691"><b>SmurfLurf</b></A> : I tried with a ZyWALL 5 and 2+, both running 4.04 firmware and it does reboot the unit... Just tried it for the fun of it, don't usually setup ZyWALL's as DNS proxy...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20798276</guid>
<pubDate>Wed, 16 Jul 2008 01:08:52 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20790364</link>
<description><![CDATA[<A HREF="/useremail/u/226051"><b>bbarrera</b></A> : No problems here on USG300 but that is likely because I'm running djbdns as dns cache on my LAN, and not using any DNS on the ZyWALL USG300.<br><br>Unlike BIND and Microsoft DNS the djbdns dns cache has *never* been vulnerable to this exploit, and is credited with identifying the dns system design flaw and fix many years ago.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20790364</guid>
<pubDate>Mon, 14 Jul 2008 16:39:16 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20790229</link>
<description><![CDATA[<A HREF="/useremail/u/755055"><b>OZO</b></A> : Thank you, guys, for confirmation!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20790229</guid>
<pubDate>Mon, 14 Jul 2008 16:10:19 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20773689</link>
<description><![CDATA[<A HREF="/useremail/u/1161423"><b>dslpartner</b></A> : Contact ZyXEL and tell them about the bug, until then try to set static dns servers on your hosts, instead of using the DNS proxy in the device.<br><small>--<br>"Perl is executable line noise, Python is executable pseudo-code."</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20773689</guid>
<pubDate>Fri, 11 Jul 2008 04:59:54 EDT</pubDate>
</item>

<item>
<title>Re: DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20772735</link>
<description><![CDATA[<A HREF="/useremail/u/1191134"><b>MVS</b></A> : I noticed the same problem on a ZyWALL 2 Plus using the latest firmware (V4.04(XU.1)) when using its IP as my DNS server.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20772735</guid>
<pubDate>Thu, 10 Jul 2008 22:20:35 EDT</pubDate>
</item>

<item>
<title>DNS checker reboots ZyWALL</title>
<link>http://www.dslreports.com/forum/remark,20767898</link>
<description><![CDATA[<A HREF="/useremail/u/755055"><b>OZO</b></A> : Tried many times DNS checker from this site - <A HREF="http://www.doxpara.com/">DoxPara Research</a> (mentioned in this thread - <A HREF="http://www.dslreports.com/forum/r20761140-Internet-flaw-could-let-hackers-take-over-the-Web">Internet flaw could let hackers take over the Web</a>) and every time my ZyWALL 5 rebooted. What's the heck?<br><br>I run the test with IE (or FireFox, yielding the same result) from WXP computer. It's DHCP client, which is getting DNS, pointing to ZyWALL.<br><br>Can anybody confirm it?<br><br>ZyWALL 5:<br>Bootbase Version V1.08 | 01/28/2005 <br>Firmware Version V4.04(XD.0) | 03/28/2008 <br><small>--<br>Keep it simple, it'll become complex by itself...</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20767898</guid>
<pubDate>Thu, 10 Jul 2008 00:42:06 EDT</pubDate>
</item>

</channel>
</rss>
