From: Mohamed Eldesoky <eldesoky.lists@gmail.com>
To: Askar <askarali@gmail.com>, netfilter <netfilter@lists.netfilter.org>
Subject: Re: DNS rules
Date: Sun, 1 May 2005 19:12:58 +0300 [thread overview]
Message-ID: <1403218a05050109123b8d08bc@mail.gmail.com> (raw)
In-Reply-To: <a0f69e505050103332635a25b@mail.gmail.com>
I didn't understand that part !!
On 5/1/05, Askar <askarali@gmail.com> wrote:
> oops too quick to hit te Send buttong :)
>
> if you going to set
> #resolv-file=
> in /etc/dnsmasq then don't forget to repace it something
>
> resolv-file=/etc/mydnsservers (the file that holding the IPs of your
> ISP dns servers)
>
> regards
>
>
> On 5/1/05, Askar <askarali@gmail.com> wrote:
> > dnsmasq would be a bit off topic here. :)
> > you can download it from ....
> > http://thekelleys.org.uk/dnsmasq/doc.html (I will prefer the source)
> > After extracting the source, read "README" for howto install its
> > pretty straight forward.
> > ./configure; make install (needed)
> >
> > this will copy "dnsmasq" binary /usr/sbin , which needed to running
> > the dnsmasq daemon by type "dnsmasq" as root.
> >
> > You can find the configuration file in /etc/dnsmasq.conf
> >
> > You only have to change the line...
> >
> > # Change this line if you want dns to get its upstream servers from
> > # somewhere other that /etc/resolv.conf
> > #resolv-file=
> >
> > Note is not necessary coz if you don't set "resolv-fle=" , dnsmasq
> > will read /etc/resolv.conf for upstream dns servers (where you have
> > already specified your ISP dns IPs)
> > If you prefer to set "resolv-file=" tag then here are the setups
> >
> > #vi /etc/mydnsserver (create a file where you have to hard code the
> > ips of your ISP dns servers
> >
> > in the file type
> >
> > nameserver xxx.xxx.xxx.xx (replace xxx with the ip)
> > nameserver xxx.xxx.xxxx.xx (specify as many dns servers you wants)
> >
> > then in /etc/resolv.conf , delete all the entries and type ...
> >
> > nameserver 127.0.0.1
> >
> > Now start dnsmasq , and try to confirm that its working by "dig, host,
> > nslook etc)
> >
> > You can also use dnsmasq as DHCP server ;)
> >
> > Now you have to tell iptables to allow upd port 53 hmmmm
> >
> > iptables -A INPUT -p udp -s 192.168.2.0/24 --dport 53 -j ACCEPT (for client)
> > iptables -A OUTPUT -p udp --dport 53 -j ACCEPT (dnsmasq towards your ISP dns)
> >
> > Hope this will helps
> >
> > Regards
> > Askar
> >
> > On 5/1/05, varun_saa@vsnl.net <varun_saa@vsnl.net> wrote:
> > >
> > >
> > > ----- Original Message -----
> > > From: Askar <askarali@gmail.com>
> > > Date: Sunday, May 1, 2005 3:22 pm
> > > Subject: Re: DNS rules
> > >
> > > > Again it depends, how you setup your default policies. In case you are
> > > > using recommended "default DROP" then you have to tell iptables to
> > > > allow "udp 53" towards your ISP.
> > > >
> > > > iptables -A FORWARD -p udp --dport 53 -j ACCEPT
> > > >
> > > >
> > > > If you are running a small LAN then running a cache only dns on your
> > > > gateway would be beneficial, (that it will cache the lookups)
> > > >
> > > > dnsmasq is excellent cache only dns server and i'm sure you would get
> > > > is running within 10 minutes.
> > > > you can also use bind in cache only mode.
> > > >
> > > Thanks
> > >
> > > Can you elaborate on dnsmasq. Please.
> > >
> > > Varun
> > >
> > >
> >
> > --
> > I love deadlines. I like the whooshing sound they make as they fly by.
> > Douglas Adams
> >
>
> --
> I love deadlines. I like the whooshing sound they make as they fly by.
> Douglas Adams
>
>
--
Mohamed Eldesoky
www.eldesoky.net
RHCE
next prev parent reply other threads:[~2005-05-01 16:12 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <915b3891601a.91601a915b38@vsnl.net>
2005-05-01 10:30 ` DNS rules Askar
2005-05-01 10:33 ` Askar
2005-05-01 16:12 ` Mohamed Eldesoky [this message]
2005-05-01 9:33 varun_saa
2005-05-01 9:52 ` Askar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1403218a05050109123b8d08bc@mail.gmail.com \
--to=eldesoky.lists@gmail.com \
--cc=askarali@gmail.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox