I believe this to be the case with both bind 8 and bind 4,
when running as a caching nameserver.
Linux defaults to using high ports when querying the root
nameservers, as described in the DNS HOWTO. The problem
comes when Linux boxes are behind firewalls that deny
connectionless traffic on high ports from the outside - in
other words, the firewalls filter out the DNS response from
the root nameservers.
Other operating systems (other *nixes too) make these
queries via UDP to and from 53. This issue is causing us
some problems in my enterprise, due to the supurrious
firewall hits we're getting.
Can the default behavior please be modified such that these
queries go out on UDP 53. Thanks!
This isn't going to be fixed in Red Hat 6.1. I'm preserving the
report by resolving to REMIND.