> I did this back in the 1990s because it worked around occasional interop
> problems, I think caused by over-enthusiastic firewall configurations that
> thought all DNS (queries and responses) should be on port 53. Several
> years ago I found that things had changed and the popular over-
> enthusiastic firewall configuration requires DNS query source ports to be
> greater than 1023.

Both firewall configuration are broken.  You don't look at source
ports if you are offering a service.

