Linux Netfilter discussions
 help / color / mirror / Atom feed
* DNS question
@ 2004-03-01 19:46 John Black
  2004-03-01 20:27 ` Antony Stone
  0 siblings, 1 reply; 11+ messages in thread
From: John Black @ 2004-03-01 19:46 UTC (permalink / raw)
  To: netfilter

I'm trying to setup DNS for domain.  Is there a mailing list or some really good
documentation online on setting up DNS with only one static ip address?


thanks
John



http://www.arbbs.net/


^ permalink raw reply	[flat|nested] 11+ messages in thread
* dns question
@ 2004-11-18 12:32 Peter Marshall
  2004-11-18 13:44 ` Jason Opperisano
  2004-11-18 13:50 ` Jason Opperisano
  0 siblings, 2 replies; 11+ messages in thread
From: Peter Marshall @ 2004-11-18 12:32 UTC (permalink / raw)
  To: netfilter

I am sure this is a stupid question ...but I will ask anyway.  Should I be
allowing my dns server (in my dmz) connect to root servers ?   At the moment
it is being bloced, and the only thing it can connect to is my ISP's DNS
server.  Basically, my dns server serves requests for servers in my dmz for
my internal users.  If it can't find the hit, it passs the request on to my
ISP's ... I am trying to clean up my firewall logs, and noticed that the DNS
server is always trying to query root servers.  I was just not sure if this
should be allowed.  If it is not, (and I suspect there is no need to) Is
there a way to make my DNS server stop quering the root servers ?

PS  DNS is a rh9 box running bind.


Thanks,
Peter





^ permalink raw reply	[flat|nested] 11+ messages in thread
* RE: DNS question
@ 2004-03-01 20:29 Daniel Chemko
  0 siblings, 0 replies; 11+ messages in thread
From: Daniel Chemko @ 2004-03-01 20:29 UTC (permalink / raw)
  To: black, netfilter


John Black wrote:
> I'm trying to setup DNS for domain.  Is there a mailing list or some
> really good documentation online on setting up DNS with only one
> static ip address?  

Try www.isc.org if you use bind. That's all I needed to set up a quite
complex DNS setup from 0 knowledge. I guess the Oreilly book helped as
well.


^ permalink raw reply	[flat|nested] 11+ messages in thread
* DNS question
@ 2003-02-06 15:21 Reed Wiedower
  2003-02-06 16:05 ` Maciej Soltysiak
  0 siblings, 1 reply; 11+ messages in thread
From: Reed Wiedower @ 2003-02-06 15:21 UTC (permalink / raw)
  To: 'netfilter@lists.netfilter.org'

I'm having some trouble with DNS queries making it through the filters...if
I allow connections out to use udp port 53, that should allow clients inside
the firewall to query external dns servers for information, correct? Do I
need to open any other ports? (Of course, I have "related, established"
open, so I assume the DNS server response will work properly). Am I missing
somthing?

end of line,

Reed


reed wiedower
reed.wiedower@peyser.com
peyser.com
202.638.3730x115



^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2004-11-18 13:50 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-03-01 19:46 DNS question John Black
2004-03-01 20:27 ` Antony Stone
2004-03-02  0:54   ` John Black
  -- strict thread matches above, loose matches on Subject: below --
2004-11-18 12:32 dns question Peter Marshall
2004-11-18 13:44 ` Jason Opperisano
2004-11-18 13:49   ` a.ledvinka
2004-11-18 13:50   ` Peter Marshall
2004-11-18 13:50 ` Jason Opperisano
2004-03-01 20:29 DNS question Daniel Chemko
2003-02-06 15:21 Reed Wiedower
2003-02-06 16:05 ` Maciej Soltysiak

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox