Beginning Tuesday July 11, 2006, access to the EECS caching DNS (Domain Name Server or Domain Name System) servers cronus and rhea will be restricted to campus IP addresses.
If you have a system off-campus, you will not be able to use cronus and rhea for DNS service. Instead you will need to configure your off-campus system to utilize your ISP’s name servers.
This action (restricting access to the EECS caching DNS servers) is occuring following the campus IS&T’s lead of restricting access to the main campus caching DNS servers, ns1.berkeley.edu (188.8.131.52, 184.108.40.206) and ns2.berkeley.edu (220.127.116.11, 18.104.22.168) beginning July 1, 2006.
It is currently considered a “best practice” to restrict access to caching DNS servers. DNS service on cronus and rhea has been abused from off-campus IP addresses. Because of the security risks associated with allowing anyone to access the caching DNS servers, many groups are restricting access to their caching DNS servers including UCLA, the University of Oregon and the University of Virginia.
IS&T has documented details and reasons behind why it is necessary to restrict access to caching DNS servers:
Current cronus and rhea IP addresses include:
cronus interfaces rhea interfaces cronus-32 22.214.171.124 rhea-32 126.96.36.199 cronus-33 188.8.131.52 rhea-33 184.108.40.206 cronus-34 220.127.116.11 rhea-34 18.104.22.168 cronus-35 22.214.171.124 rhea-35 126.96.36.199 cronus-36 188.8.131.52 rhea-36 184.108.40.206 cronus-37 220.127.116.11 rhea-37 18.104.22.168 cronus-38 22.214.171.124 rhea-38 126.96.36.199 cronus-40 188.8.131.52 rhea-40 184.108.40.206 cronus-41 220.127.116.11 rhea-41 18.104.22.168 cronus-42 22.214.171.124 rhea-42 126.96.36.199 cronus-43 188.8.131.52 rhea-43 184.108.40.206 cronus-47 220.127.116.11 rhea-47 18.104.22.168 cronus-48 22.214.171.124 rhea-48 126.96.36.199 cronus-62 188.8.131.52 rhea-62 184.108.40.206 cronus-63 220.127.116.11 rhea-63 18.104.22.168 cronus-112 22.214.171.124 rhea-112 126.96.36.199 cronus-132 188.8.131.52 rhea-132 184.108.40.206 cronus-134 220.127.116.11 rhea-134 18.104.22.168 cronus-153 22.214.171.124 rhea-153 126.96.36.199 cronus-168 188.8.131.52 rhea-168 184.108.40.206 cronus-171 220.127.116.11 rhea-171 18.104.22.168 cronus-cusg 22.214.171.124 rhea-cusg 126.96.36.199 cronus-169-229-63 188.8.131.52 rhea-169-229-63 184.108.40.206
Caching DNS service will also end from IP address 220.127.116.11 on Tuesday July 11, 2006.
Please update your off-campus systems accordingly.