elektra
elektra copied to clipboard
SecurityGroups: DNS should be TCP+UDP
The SG wizard for DNS should create rules for UDP+TCP, currently it only creates one for TCP:
I originally requested this change - but IMHO we need NO TCP rule at all - and only an egress-UDP-port53 rule for DNS queries!
it will also use TCP when the answer size exceeds the packet size, see https://tools.ietf.org/html/rfc7766
Bump: stumbled over this as well. I think linux can do a TCP fallback, but windows can not, and ideally it would be both.