When a static packet filter for Domain Name System (DNS) traffic is defined in Microsoft Internet Security and Acceleration Server with dynamic packet filtering enabled, DNS traffic is able to flow into a network protected by Internet Security and Acceleration Server. However, when the static packet filter for DNS is removed, Internet Security and Acceleration Server is still able to generate DNS queries and receive responses.
↑ Back to the top
Static and dynamic filters serve different general purposes. When you use dynamic filtering, Internet Security and Acceleration Server creates and removes packet filters on the external interface when necessary. As a result, internal clients are able to generate successful queries. Static packet filters, however, are used to receive incoming requests from external clients.
↑ Back to the top