View previous topic :: View next topic |
Author |
Message |
nihilo Apprentice
![Apprentice Apprentice](/images/ranks/rank_rect_2.gif)
![](images/avatars/128180955946f94da94deca.gif)
Joined: 05 Nov 2002 Posts: 168 Location: berkeley, ca, usa
|
Posted: Sun Dec 29, 2002 5:02 am Post subject: dns & firewall configuration question |
|
|
I've checked google and the forums for firewall configuration to allow dns, but I cannot seem to get my firewall (iptables) configured properly so that the dns queries can get out and in. I have tried opening ports 53, 67, and 68, but dns still sometimes does not work. Stopping the firewall immediately fixes the problem. I have a cable modem (at&t broadband). Any other at&t broadband customers who could tell me how they have their firewall configured to use at&t's dns servers (which ports, protocols, etc.)??
thanks... |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
delta407 Bodhisattva
![Bodhisattva Bodhisattva](/images/ranks/rank-bodhisattva.gif)
![](images/avatars/d02a5f053d2286340332d.jpg)
Joined: 23 Apr 2002 Posts: 2876 Location: Chicago, IL
|
Posted: Sun Dec 29, 2002 5:34 am Post subject: |
|
|
Make sure port 53, UDP, can get in and out. Are you simply firewalling or doing some NAT as well? _________________ I don't believe in witty sigs. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Xor Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/gallery/Zelda/Zelda_-_Link.jpg)
Joined: 07 Jul 2002 Posts: 144
|
Posted: Sun Dec 29, 2002 3:37 pm Post subject: |
|
|
my advise
these apply for TCP and UDP and are meant to be used in a statefull firewall
outbound: from highports and dns port to dns port
inbound: to dns port from highports and dns port
regards
xor |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
TrippyZ n00b
![n00b n00b](/images/ranks/rank_rect_0.gif)
Joined: 04 Dec 2002 Posts: 38
|
Posted: Sun Dec 29, 2002 8:16 pm Post subject: |
|
|
Please post a copy of your setup script, or the output of iptables-save.
In the meantime, you only need to let the query out with a '-p udp --dport 53', as you usually let the replies reenter through a ' ESTABLISHED, RELATED -j ALLOW'
I alway like to have a sniff with tcpdump anyhow just to find out a bit more of whats going on. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
nihilo Apprentice
![Apprentice Apprentice](/images/ranks/rank_rect_2.gif)
![](images/avatars/128180955946f94da94deca.gif)
Joined: 05 Nov 2002 Posts: 168 Location: berkeley, ca, usa
|
Posted: Mon Dec 30, 2002 10:36 pm Post subject: thanks, success |
|
|
thanks for the help. I am using kmyfirewall, and it seems that the new script (with dns ports open) wasn't being used after all. Now that I made sure that outbound on 53 is allowed, it seems to be working.
thanks again. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|