Cisco CCNA (200-301)Network FundamentalsMedium

A DNS administrator needs to permit zone transfers between a primary and secondary DNS server through a firewall. Regular DNS queries already work. Which protocol and port combination must be added to the firewall rule?

  1. AUDP port 53
  2. BTCP port 43
  3. CTCP port 53
  4. DUDP port 43
Show answer & explanation

Correct answer: C. TCP port 53

DNS queries typically use UDP port 53, but zone transfers (AXFR/IXFR) between DNS servers require a reliable, ordered connection, so they use TCP port 53. Since queries already work, the missing rule must specifically permit TCP 53.

Why the other options are wrong

  • A. UDP 53 is already used for standard queries and is not the missing piece for zone transfers.
  • B. TCP port 43 is used by WHOIS, unrelated to DNS zone transfers.
  • D. UDP port 43 is also associated with WHOIS, not DNS.

DNS Zone Transfer

The process of copying DNS zone data from a primary to a secondary name server, which requires TCP because of its reliability guarantees.

  • Standard DNS queries: UDP/53 (TCP/53 for large responses)
  • Zone transfers (AXFR/IXFR): TCP/53 always
  • TCP is chosen for zone transfers due to reliable delivery of larger datasets

Memory trick: Zone transfers need a Ticket (TCP) for guaranteed delivery.

More Network Fundamentals questions