Cisco CCNA (200-301)Network FundamentalsMedium
A DNS administrator needs to permit zone transfers between a primary and secondary DNS server through a firewall. Regular DNS queries already work. Which protocol and port combination must be added to the firewall rule?
- AUDP port 53
- BTCP port 43
- CTCP port 53
- DUDP port 43
Show answer & explanationAnswer & explanation
Correct answer: C. TCP port 53
DNS queries typically use UDP port 53, but zone transfers (AXFR/IXFR) between DNS servers require a reliable, ordered connection, so they use TCP port 53. Since queries already work, the missing rule must specifically permit TCP 53.
Why the other options are wrong
- A. UDP 53 is already used for standard queries and is not the missing piece for zone transfers.
- B. TCP port 43 is used by WHOIS, unrelated to DNS zone transfers.
- D. UDP port 43 is also associated with WHOIS, not DNS.
DNS Zone Transfer
The process of copying DNS zone data from a primary to a secondary name server, which requires TCP because of its reliability guarantees.
- Standard DNS queries: UDP/53 (TCP/53 for large responses)
- Zone transfers (AXFR/IXFR): TCP/53 always
- TCP is chosen for zone transfers due to reliable delivery of larger datasets
Memory trick: Zone transfers need a Ticket (TCP) for guaranteed delivery.