LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 05-02-2010, 11:23 AM   #1
ciberrust
Member
 
Registered: Dec 2003
Location: AUS
Distribution: CentOs, OpenSuse, Ubuntu, Leopard :D
Posts: 97

Rep: Reputation: 15
DNS Server iptables


Hello , i made a search here and in other places but can't find the answer.

I have a server wich is dns http mail
I have iptables running with the propper ports open to allow traffic and see web and mail as well as ssh etc...

The thing i can't get to work is the dns , when the fw is down the webpage loads fine (by it's domain name)
And it works fine with ip all the time.

I have tried opening port 53 on udp and tcp but it does not work.
This are my rules right now.
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- xxay.xxxred.com 201.xxx.xxx.xxx
DROP icmp -- anywhere 201.xxx.xxxx.xxx
ACCEPT tcp -- 201.2xx.xx.xx 201.xxx.xxx.xxx tcp dpt:ssh
ACCEPT tcp -- 78.2xx.xx.xx 201.xxxxxxxxx tcp dpts:ftp-data:ftp
ACCEPT tcp -- 82.2xx.xx.xx 201.xx0xx.xx tcp dpts:ftp-data:ftp
ACCEPT tcp -- 193xx.xx.xx 201.xx0.xx.xx tcp dpts:ftp-data:ftp
ACCEPT tcp -- anywhere 201.2xx.xx.xx tcp dpt:http
ACCEPT tcp -- anywhere 201.xx.xx.xx0 tcp dptop3
ACCEPT tcp -- anywhere 201.xxx.xx.xx.xx0 tcp dpt:smtp
ACCEPT tcp -- 78.xxx.xx.xx 20x.xxx.xxx.x0 tcp dpt:ssh
ACCEPT tcp -- 82.xx.xx.xx. 201.xx.xx..xx0 tcp dpt:ssh
ACCEPT tcp -- 193.xxx.xx.xx.x 201xx.xx.xx0 tcp dpt:ssh
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable

Chain FORWARD (policy ACCEPT)
target prot opt source destination
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable

Chain OUTPUT (policy ACCEPT)
target prot opt source destination
 
Old 05-02-2010, 11:48 AM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Stick a LOG rule right before the REJECT one and check the log when failure occurs.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
IPTables: block all dns requests except to the server(s) I specify Kage_ Linux - Networking 4 08-25-2019 02:18 PM
plz give me some firewall(iptables or ipchain) for my dns,web & mail server fadu Linux - Security 6 07-03-2009 11:44 PM
LXer: Find out DNS Server Version With DNS Server Fingerprinting Tool LXer Syndicated Linux News 0 12-21-2007 05:30 PM
LXer: Find out DNS Server Version With DNS Server Fingeprinting Tool LXer Syndicated Linux News 0 12-21-2007 04:50 PM
Iptables and DNS server trouble in LAN bence8810 Linux - Server 7 03-12-2007 06:01 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 01:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration