Beginning Tuesday July 11, 2006, access to the EECS caching DNS (Domain Name Server or Domain Name System) servers cronus and rhea will be restricted to campus IP addresses.
If you have a system off-campus, you will not be able to use cronus and rhea for DNS service. Instead you will need to configure your off-campus system to utilize your ISP’s name servers.
This action (restricting access to the EECS caching DNS servers) is occuring following the campus IS&T’s lead of restricting access to the main campus caching DNS servers, ns1.berkeley.edu (184.108.40.206, 220.127.116.11) and ns2.berkeley.edu (18.104.22.168, 22.214.171.124) beginning July 1, 2006.
It is currently considered a “best practice” to restrict access to caching DNS servers. DNS service on cronus and rhea has been abused from off-campus IP addresses. Because of the security risks associated with allowing anyone to access the caching DNS servers, many groups are restricting access to their caching DNS servers including UCLA, the University of Oregon and the University of Virginia.
IS&T has documented details and reasons behind why it is necessary to restrict access to caching DNS servers:
Current cronus and rhea IP addresses include:
cronus interfaces rhea interfaces cronus-32 126.96.36.199 rhea-32 188.8.131.52 cronus-33 184.108.40.206 rhea-33 220.127.116.11 cronus-34 18.104.22.168 rhea-34 22.214.171.124 cronus-35 126.96.36.199 rhea-35 188.8.131.52 cronus-36 184.108.40.206 rhea-36 220.127.116.11 cronus-37 18.104.22.168 rhea-37 22.214.171.124 cronus-38 126.96.36.199 rhea-38 188.8.131.52 cronus-40 184.108.40.206 rhea-40 220.127.116.11 cronus-41 18.104.22.168 rhea-41 22.214.171.124 cronus-42 126.96.36.199 rhea-42 188.8.131.52 cronus-43 184.108.40.206 rhea-43 220.127.116.11 cronus-47 18.104.22.168 rhea-47 22.214.171.124 cronus-48 126.96.36.199 rhea-48 188.8.131.52 cronus-62 184.108.40.206 rhea-62 220.127.116.11 cronus-63 18.104.22.168 rhea-63 22.214.171.124 cronus-112 126.96.36.199 rhea-112 188.8.131.52 cronus-132 184.108.40.206 rhea-132 220.127.116.11 cronus-134 18.104.22.168 rhea-134 22.214.171.124 cronus-153 126.96.36.199 rhea-153 188.8.131.52 cronus-168 184.108.40.206 rhea-168 220.127.116.11 cronus-171 18.104.22.168 rhea-171 22.214.171.124 cronus-cusg 126.96.36.199 rhea-cusg 188.8.131.52 cronus-169-229-63 184.108.40.206 rhea-169-229-63 220.127.116.11
Caching DNS service will also end from IP address 18.104.22.168 on Tuesday July 11, 2006.
Please update your off-campus systems accordingly.