From mboxrd@z Thu Jan 1 00:00:00 1970 From: Neil Hodge Subject: Tightening up outgoing traffic Date: 15 Oct 2002 05:47:14 -0700 Sender: netfilter-admin@lists.netfilter.org Message-ID: <1034686034.15446.38.camel@localhost.localdomain> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org All: I am running directly off the firewall box. I currently have the following: iptables -P OUTPUT ACCEPT When I change to this: iptables -P OUTPUT DROP iptables -A OUTPUT -p tcp --destination-port http -j ACCEPT I keep getting "domainname can not be found. Please check the name and try again" from my browser. This only happens for new web sites (i.e., Yahoo works fine). As this seems somewhat like a DNS issue, I tried adding this: iptables -A OUTPUT -p tcp --destination-port nameserver -j ACCEPT but it didn't work. Any ideas? Thanks. Neil Hodge