Re: bind 9.2.1 dig problems
From: David Efflandt (efflandt_at_xnet.com)
Date: 10/23/03
- Next message: David Efflandt: "Re: Caching only name server"
- Previous message: ynotssor: "Re: Caching only name server"
- In reply to: mark stephens: "Re: bind 9.2.1 dig problems"
- Next in thread: mark stephens: "Re: bind 9.2.1 dig problems"
- Reply: mark stephens: "Re: bind 9.2.1 dig problems"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: Thu, 23 Oct 2003 01:02:22 +0000 (UTC)
On 22 Oct 2003 07:39:00 -0700, mark stephens <mark_r_stephens@yahoo.com> wrote:
> iptables -L returns this for domain:
>
> ACCEPT udp -- opalfire anywhere udp
> spt:domain dpts:1025:65535
> ACCEPT udp -- ns1.mindspring.com anywhere udp
> spt:domain dpts:1025:65535
> ACCEPT udp -- ns2.mindspring.com anywhere udp
> spt:domain dpts:1025:65535
OK, which chain is that (OUTPUT?)? That appears to allow opalfire to
connect its port 53 (domain) to a limited range of ports anywhere, but
where is the rule to ACCEPT any port from anywhere to dpt:domain on
opalfire? Your tcpdump posted separately confirms that incoming domain
(port 53) requests are being refused as network unreachable.
> I'm still playing with tcpdump to see what's coming through.
>
> efflandt@xnet.com (David Efflandt) wrote in message news:<slrnbpbf6g.ebf.efflandt@typhoon.xnet.com>...
>> On 21 Oct 2003 08:40:08 -0700, mark stephens <mark_r_stephens@yahoo.com
>
> Check the output of 'iptables -L' on your nameserver. It could be running
>> a default firewall that only allows access from local IPs.
>>
>> Or run tcpdump and do a query from outside (internet) to see if there is
>> any sign of a hit and/or lack of response.
-- David Efflandt - All spam ignored http://www.de-srv.com/ http://www.autox.chicago.il.us/ http://www.berniesfloral.net/ http://cgi-help.virtualave.net/ http://hammer.prohosting.com/~cgi-wiz/
- Next message: David Efflandt: "Re: Caching only name server"
- Previous message: ynotssor: "Re: Caching only name server"
- In reply to: mark stephens: "Re: bind 9.2.1 dig problems"
- Next in thread: mark stephens: "Re: bind 9.2.1 dig problems"
- Reply: mark stephens: "Re: bind 9.2.1 dig problems"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
|