johnPostel
Technical User
Hello, I am fairly new to cisco routers. I work for a small office which has a cisco router. We have two DNS servers on the internal network. Here's my situation: I want to restrict zone transfers from all untrusted sources. Essentially what i want to do is have just the primary + secondary DNS servers be able to talk to each other, and refuse incoming traffic on port 53. I hear I can use "extended" ACL's to accomplish this, but I'm not sure how. I'm very grateful for any suggestions or help!