LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 08-18-2015, 06:07 AM   #1
positiveman87
LQ Newbie
 
Registered: Aug 2015
Posts: 2

Rep: Reputation: Disabled
iptables caching domain?


Hi guys

I am using a dynamic DNS service so my home dynamic IP can be linked to a domain.

I then have that domain in my IPTABLES firewall to allow all access.

The problem I am having is I think iptables is caching the domain. E.g if I login in the day and then again in the night.. iptables will still have the IP address from the day even though it has changed and updated via the dynamic DNS

The only way I have found to get around this is restart iptables. It works fine then.

Is there a way to force iptables not to cache a domain?

I don't believe it is linux dns caching as I used DIG which returns the correct IP address for the domain, whilst iptables still appears to see the old one.
 
Old 08-18-2015, 06:32 AM   #2
smallpond
Senior Member
 
Registered: Feb 2011
Location: Massachusetts, USA
Distribution: Fedora
Posts: 4,140

Rep: Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263
You want iptables to do a DNS lookup on every packet? Are you aware that DNS lookups go through iptables?
 
Old 08-18-2015, 07:24 AM   #3
positiveman87
LQ Newbie
 
Registered: Aug 2015
Posts: 2

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by smallpond View Post
You want iptables to do a DNS lookup on every packet? Are you aware that DNS lookups go through iptables?
What would be the best way to achieve my goal?

I need a Dynamic DNS service to link my dynamic IP to a static domain but it is of no use if iptables can't retrieve the latest dns record for the said domain.

Perhaps if there was a way to specify MUST DO A DNS LOOKUP EVERYTIME FOR THIS PARTICULAR DOMAIN?
 
Old 08-18-2015, 12:27 PM   #4
smallpond
Senior Member
 
Registered: Feb 2011
Location: Massachusetts, USA
Distribution: Fedora
Posts: 4,140

Rep: Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263
Best way would be to have your dynamic dhcp client restart iptables when it gets a new IP.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
IPtables - block subdomains (a.domain.com, b.domain.com, c.domain.com,...) benjalien Linux - Networking 6 06-24-2009 07:03 AM
dnscache - how to stop caching a certain domain diadomraz Linux - Server 0 11-04-2008 12:10 PM
IPTables logging with domain resolution? SlowCoder Linux - Security 2 11-15-2007 11:36 AM
removal of caching nameserver does not stop domain resolution jhwilliams Linux - Software 1 08-10-2007 09:16 PM
iptables allow all from domain Imiro Linux - Security 6 09-29-2003 01:50 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 01:16 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration