From: Askar <askarali@gmail.com>
To: netfilter <netfilter@lists.netfilter.org>
Subject: Re: DNS rules
Date: Sun, 1 May 2005 15:33:52 +0500 [thread overview]
Message-ID: <a0f69e505050103332635a25b@mail.gmail.com> (raw)
In-Reply-To: <a0f69e505050103303d959c4e@mail.gmail.com>
oops too quick to hit te Send buttong :)
if you going to set
#resolv-file=
in /etc/dnsmasq then don't forget to repace it something
resolv-file=/etc/mydnsservers (the file that holding the IPs of your
ISP dns servers)
regards
On 5/1/05, Askar <askarali@gmail.com> wrote:
> dnsmasq would be a bit off topic here. :)
> you can download it from ....
> http://thekelleys.org.uk/dnsmasq/doc.html (I will prefer the source)
> After extracting the source, read "README" for howto install its
> pretty straight forward.
> ./configure; make install (needed)
>
> this will copy "dnsmasq" binary /usr/sbin , which needed to running
> the dnsmasq daemon by type "dnsmasq" as root.
>
> You can find the configuration file in /etc/dnsmasq.conf
>
> You only have to change the line...
>
> # Change this line if you want dns to get its upstream servers from
> # somewhere other that /etc/resolv.conf
> #resolv-file=
>
> Note is not necessary coz if you don't set "resolv-fle=" , dnsmasq
> will read /etc/resolv.conf for upstream dns servers (where you have
> already specified your ISP dns IPs)
> If you prefer to set "resolv-file=" tag then here are the setups
>
> #vi /etc/mydnsserver (create a file where you have to hard code the
> ips of your ISP dns servers
>
> in the file type
>
> nameserver xxx.xxx.xxx.xx (replace xxx with the ip)
> nameserver xxx.xxx.xxxx.xx (specify as many dns servers you wants)
>
> then in /etc/resolv.conf , delete all the entries and type ...
>
> nameserver 127.0.0.1
>
> Now start dnsmasq , and try to confirm that its working by "dig, host,
> nslook etc)
>
> You can also use dnsmasq as DHCP server ;)
>
> Now you have to tell iptables to allow upd port 53 hmmmm
>
> iptables -A INPUT -p udp -s 192.168.2.0/24 --dport 53 -j ACCEPT (for client)
> iptables -A OUTPUT -p udp --dport 53 -j ACCEPT (dnsmasq towards your ISP dns)
>
> Hope this will helps
>
> Regards
> Askar
>
> On 5/1/05, varun_saa@vsnl.net <varun_saa@vsnl.net> wrote:
> >
> >
> > ----- Original Message -----
> > From: Askar <askarali@gmail.com>
> > Date: Sunday, May 1, 2005 3:22 pm
> > Subject: Re: DNS rules
> >
> > > Again it depends, how you setup your default policies. In case you are
> > > using recommended "default DROP" then you have to tell iptables to
> > > allow "udp 53" towards your ISP.
> > >
> > > iptables -A FORWARD -p udp --dport 53 -j ACCEPT
> > >
> > >
> > > If you are running a small LAN then running a cache only dns on your
> > > gateway would be beneficial, (that it will cache the lookups)
> > >
> > > dnsmasq is excellent cache only dns server and i'm sure you would get
> > > is running within 10 minutes.
> > > you can also use bind in cache only mode.
> > >
> > Thanks
> >
> > Can you elaborate on dnsmasq. Please.
> >
> > Varun
> >
> >
>
> --
> I love deadlines. I like the whooshing sound they make as they fly by.
> Douglas Adams
>
--
I love deadlines. I like the whooshing sound they make as they fly by.
Douglas Adams
next prev parent reply other threads:[~2005-05-01 10:33 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <915b3891601a.91601a915b38@vsnl.net>
2005-05-01 10:30 ` DNS rules Askar
2005-05-01 10:33 ` Askar [this message]
2005-05-01 16:12 ` Mohamed Eldesoky
2005-05-01 9:33 varun_saa
2005-05-01 9:52 ` Askar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a0f69e505050103332635a25b@mail.gmail.com \
--to=askarali@gmail.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox