LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 06-08-2004, 12:39 PM   #1
raven02
LQ Newbie
 
Registered: Jun 2004
Posts: 1

Rep: Reputation: 0
iptables - not broadcasting for dns queries


Greetings:

I currently have a RH9 box setup as a firewall and DNS server. Using iptables for firewalling and Bind 9 for name resolution, I have my internal dns working great. I can resolve my www(dot)xxx(dot)net and ftp(dot)xxx(dot)net fine from internal machines and server so I believe my dns is setup correctly. My problem stems from the outside network(internet) being able to resolve to my dns server. Here is how my iptables look...

[root@ginkgo /]# iptables --list
Chain INPUT (policy ACCEPT)
target prot opt source destination
RH-Lokkit-0-50-INPUT all -- anywhere anywhere

Chain FORWARD (policy ACCEPT)
target prot opt source destination
RH-Lokkit-0-50-INPUT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere

Chain OUTPUT (policy ACCEPT)
target prot opt source destination

Chain RH-Lokkit-0-50-INPUT (2 references)
target prot opt source destination
ACCEPT udp -- localhost.localdomain anywhere udp spt:domain dpt
s:1025:65535
ACCEPT tcp -- anywhere anywhere tcp dpt:smtp flags:S
YN,RST,ACK/SYN
ACCEPT tcp -- anywhere anywhere tcp dpt:http flags:S
YN,RST,ACK/SYN
ACCEPT tcp -- anywhere anywhere tcp dpt:ftp flags:SY
N,RST,ACK/SYN
ACCEPT tcp -- anywhere anywhere tcp dpt:ssh flags:SY
N,RST,ACK/SYN
ACCEPT tcp -- anywhere anywhere tcp dpt:domain flags
:SYN,RST,ACK/SYN
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
ACCEPT udp -- hi-rez.ns.algx.net anywhere udp spt:domain
ACCEPT udp -- ns2.algx.net anywhere udp spt:domain
REJECT tcp -- anywhere anywhere tcp flags:SYN,RST,ACK/SYN reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp reject-with icmp-port-unreachable
[root@ginkgo /]#

Is there a reference in my itables that is blocking DNS resolution? Any help or urls for support would be appreciated.

Thanks
 
Old 06-08-2004, 11:47 PM   #2
ppuru
Senior Member
 
Registered: Mar 2003
Location: Beautiful BC
Distribution: RedHat & clones, Slackware, SuSE, OpenBSD
Posts: 1,791

Rep: Reputation: 50
Can you provide the output of

#iptables -nvL

DNS queries are UDP
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Which process is making DNS queries? TruckStuff Linux - Networking 4 11-29-2005 04:05 PM
ipv6 queries to dns peacebwitchu AIX 0 11-10-2005 06:57 PM
DNS IPv6 Queries Fail kawauso-kun Debian 1 01-15-2005 05:31 PM
DNS Queries lcplutz@wincor Linux - Networking 2 06-04-2004 06:59 AM
Some queries related to DNS(bind) coolamit78 Linux - Networking 1 12-19-2003 03:05 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 09:05 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration