From: pravin rane <pgr_80@yahoo.com>
To: Daniel Chemko <dchemko@smgtec.com>, netfilter@lists.netfilter.org
Subject: RE: How to block only MX query made to DNS server
Date: Sat, 27 Nov 2004 20:17:55 -0800 (PST) [thread overview]
Message-ID: <20041128041755.17971.qmail@web12307.mail.yahoo.com> (raw)
In-Reply-To: <7C9884991ADAE0479C14F10C858BCDF56795EA@alderaan.smgtec.com>
That is right but only when all clients are using my
DNS server. I will not be able to block MX requests if
they are using some other DNS servers which are
out-side of my network and I can not force my clients
to use only my DNS server.
Using iptables I can build a rule for certain ICMP
TYPE Packets. Is there any rule which can match DNS
query TYPE?
regards
Pravin Rane.
--- Daniel Chemko <dchemko@smgtec.com> wrote:
> pravin rane wrote:
> > Hi all,
> >
> > I want to block DNS MX query made through my
> network.
> > What iptables rule I should use.
>
> You don't use iptables to do this. named has built
> in ACL's to determine
> who can perform what oeprations. Look at bind
> 'view's for more
> information on how to properly deal with name
> resolution issues.
>
=====
--
__..-'
_.--''
_...__..-'
.'
.'
.'
.'
.------._ ;
.-"""`-.<') `-._ .'
(.--. _ `._ `'---.__.-' Fly High Till You Reach
` `;'-.-' '- ._ The Sky
.--'`` '._ - ' .
`""'-. `---' ,
''--..__ `\ Warm Regards
``''---'`\ .'
`'. ' Pravin Rane.
__________________________________
Do you Yahoo!?
Yahoo! Mail - You care about security. So do we.
http://promotions.yahoo.com/new_mail
next prev parent reply other threads:[~2004-11-28 4:17 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-11-27 21:23 How to block only MX query made to DNS server Daniel Chemko
2004-11-28 4:17 ` pravin rane [this message]
2004-11-28 6:21 ` Jason Opperisano
-- strict thread matches above, loose matches on Subject: below --
2004-11-30 10:36 hclfm
2004-11-30 11:46 ` Leonardo Rodrigues Magalhães
2004-11-30 11:50 ` pravin rane
[not found] <OFF16F8905.C3905D39-ON65256F5C.002D9EA6@pricol.co.in>
2004-11-30 8:53 ` pravin rane
2004-11-30 12:35 ` a.ledvinka
2004-11-29 18:27 Hudson Delbert J Contr 61 CS/SCBN
2004-11-30 7:26 ` pravin rane
2004-11-30 13:17 ` Jason Opperisano
2004-11-30 14:28 ` Jason Opperisano
2004-11-27 9:51 pravin rane
2004-11-28 7:40 ` Tom Marshall
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20041128041755.17971.qmail@web12307.mail.yahoo.com \
--to=pgr_80@yahoo.com \
--cc=dchemko@smgtec.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox