[squid-users] Squid binding to random udp ports > 1023

From: Steve Bremer <steveb@dont-contact.us>
Date: Wed, 6 Mar 2002 08:45:08 -0600

Hi,
        From searching the archive, I know this has be discussed
previously. However, I couldn't find a working solution to the
problem.

I recently upgraded squid and noticed that it is binding to a UDP
port above 1023 typically in the 1024 - 1040 range. In the archives,
there is mention that the internal dns resolver may be doing this.
Previously, we used the external dnsserver so we never ran into
this.

I would like to control the interface that squid is binding to for the
internal dns resolver (if that is indeed the culprit). The following
post mentioned using the udp_incoming_address to control this,
but I could not get it to work.

http://www.squid-cache.org/mail-archive/squid-users/200009/0750.html

Has anyone been able to successfully restrict which interface
squid binds to for the internal dns resolver? I would prefer not to
have it binding to all interfaces for security reasons.

We are using squid 2.4STABLE3 + patches for the recently
discovered vulnerabilities.

Thanks in advance for any help you can provide.
Steve Bremer
NEBCO, Inc.
Received on Wed Mar 06 2002 - 07:43:19 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:06:45 MST