netfilter.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* randomly changing IPs from different subnets (Google Mail)
@ 2010-06-22 18:16 Florian Effenberger
  2010-06-22 18:19 ` Jan Engelhardt
  2010-06-22 18:55 ` Jeff Largent
  0 siblings, 2 replies; 28+ messages in thread
From: Florian Effenberger @ 2010-06-22 18:16 UTC (permalink / raw)
  To: netfilter

Hi,

my default network policy is to block all outgoing traffic and only allow certain packets to pass. For some users, I'd like to open up Google Mail (imap.gmail.com:993 and smtp.gmail.com:587). However, Google's DNS give randomly out different IPs per query. Sadly, they are not all located within a subnet, but vary in all parts of the address.

If I want to have destination host based rules, how can I do this with iptables? My current idea is to run a cron job every few minutes to add the rules again with the changed IPs, but this sounds like an ugly workaround, and will clutter my user-defined chain heavily.

Is there any other approach, other than opening up all traffic to 993 and 587?

Thanks,
Florian

^ permalink raw reply	[flat|nested] 28+ messages in thread

end of thread, other threads:[~2010-06-24 16:45 UTC | newest]

Thread overview: 28+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-06-22 18:16 randomly changing IPs from different subnets (Google Mail) Florian Effenberger
2010-06-22 18:19 ` Jan Engelhardt
2010-06-22 18:30   ` Florian Effenberger
2010-06-22 19:16     ` Lars Nooden
2010-06-23  8:53       ` Florian Effenberger
2010-06-23  9:33         ` Mart Frauenlob
2010-06-23 16:46           ` Florian Effenberger
2010-06-23 11:52         ` Lars Nooden
2010-06-23 11:54           ` Jan Engelhardt
2010-06-23 13:47             ` Lars Nooden
2010-06-23 13:52               ` John Haxby
2010-06-23 14:12               ` /dev/rob0
2010-06-23 14:36                 ` Documentation (was Re: randomly changing IPs from different subnets (Google Mail)) Lars Nooden
2010-06-23 15:13                   ` /dev/rob0
2010-06-23 16:00                     ` Jan Engelhardt
2010-06-23 16:15                       ` Lars Nooden
2010-06-23 16:36                         ` Jan Engelhardt
2010-06-23 18:34                           ` Grant Taylor
2010-06-23 18:41                             ` Jan Engelhardt
2010-06-23 18:53                               ` Grant Taylor
2010-06-24  6:17                     ` Andrew Beverley
2010-06-24 16:45                       ` Grant Taylor
2010-06-23 16:44           ` randomly changing IPs from different subnets (Google Mail) Florian Effenberger
2010-06-23 18:36           ` Grant Taylor
2010-06-22 19:18     ` Jan Engelhardt
2010-06-22 18:55 ` Jeff Largent
2010-06-23  1:09   ` /dev/rob0
2010-06-23  1:22     ` Mike Lay

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).