Related anti-pattern: firewall implementers who block 53/tcp because they think only DNS zone transfers use TCP and also that allowing zone transfers is bad. Also inhibits purposeful use of TCP for ...