The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > OS Specific Forums > Linux
Google UNIX.COM


Linux RedHat, Ubuntu, SUSE, Fedora, Debian, Mandriva, Slackware, Gentoo linux, PCLinuxOS. All Linux questions here!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Help needed in IPTables firewall/router setup - Linux chandan_m Security 0 08-24-2007 03:20 PM
Linux IPTABLES help nogumo UNIX for Dummies Questions & Answers 0 06-18-2005 04:31 PM
LINUX 9 IPTABLES and DNS frankkahle UNIX for Advanced & Expert Users 1 03-03-2005 06:04 AM
IPtables Jody UNIX for Dummies Questions & Answers 3 05-31-2003 05:08 PM
how to configure a linux box as a firewall using iptables Deuce UNIX for Dummies Questions & Answers 2 11-06-2001 01:25 PM

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-02-2005
Registered User
 

Join Date: Mar 2005
Posts: 74
LINUX 9 IPTABLES and DNS

I have installed a linux 9 router/firewall and have issues with outside DNS queries making it in. here are my IPTABLE rules, can anyone make some suggestions?

ETH1 is my outside facing Interface, ETH0 is my inside facing interface.

Accept If input interface is not eth1
Accept If protocol is TCP and TCP flags ACK (of ACK) are set
Accept If protocol is UDP and input interface is eth1 and destination port is 1024:65535 and source port is 53
Accept If state of connection is ESTABLISHED
Accept If state of connection is RELATED
Accept If protocol is TCP and destination is 216.58.39.241 and input interface is eth1 and destination port is 110
Accept If protocol is TCP and destination is 216.58.39.241 and input interface is eth1 and destination port is 25
Accept If protocol is TCP and input interface is eth1 and source and destination ports are 6346
Accept If protocol is ICMP and ICMP type is source-quench
Accept If protocol is ICMP and ICMP type is time-exceeded
Accept If protocol is ICMP and ICMP type is parameter-problem
Accept If protocol is TCP and destination port is ssh
Accept If protocol is TCP and destination port is auth
Reply With Quote
Forum Sponsor
  #2 (permalink)  
Old 03-09-2005
Registered User
 

Join Date: Mar 2005
Location: india
Posts: 40
flush ur rules first.
choose ur policies like which port nos can b allowed thru eth1
u hv not mentioned sepearate rule for nic's
specify a rule with corresponding eth device
Reply With Quote
  #3 (permalink)  
Old 03-09-2005
reborg's Avatar
Administrator
 
Join Date: Mar 2005
Location: Ireland
Posts: 3,499
Quote:
Originally Posted by sriram.s
flush ur rules first.
choose ur policies like which port nos can b allowed thru eth1
u hv not mentioned sepearate rule for nic's
specify a rule with corresponding eth device
sriram.s, it can be difficult for people who do not speak English as a first language to understand this kind of reply.
Simple rules of the UNIX.COM forums:
See rule #9

You will probably need to explicity allow the DNS requests trough by allowing access on port 111.

Last edited by reborg; 03-09-2005 at 02:12 PM.
Reply With Quote
  #4 (permalink)  
Old 03-09-2005
Registered User
 

Join Date: Mar 2005
Location: india
Posts: 40
thanx for the input reborg!
but port 111 serves rpc service..?
could u pls explain in detail.
Reply With Quote
  #5 (permalink)  
Old 03-10-2005
reborg's Avatar
Administrator
 
Join Date: Mar 2005
Location: Ireland
Posts: 3,499
You will have to bear with me because it has been quite some time since I have had any need to manipulate iptables on any of my servers, but I got a bit confused between a phonecall I was on when I replied to this and your question.

What I meant to say is that you would need to allow access for UDP and TCP on port 53. Most lookups happen by UDP but some do not, and zone transfers happen exclisively by TCP.
Reply With Quote
  #6 (permalink)  
Old 03-10-2005
Registered User
 

Join Date: Mar 2005
Posts: 74
this is what I ended up doing

Accept If protocol is UDP and destination is 216.58.24.33 and destination port is 53 and source port is 1024:65535
Accept If protocol is UDP and destination port is 1024:65535 and source port is 53

Oh yeah I also changed IP to 216.58.24

Last edited by frankkahle; 03-10-2005 at 12:56 PM.
Reply With Quote
  #7 (permalink)  
Old 03-10-2005
Registered User
 

Join Date: Mar 2005
Location: india
Posts: 40
ok any way issue has been sorted out..!
keep posting....!
Reply With Quote
Google UNIX.COM
Reply

Tags
linux

Thread Tools
Display Modes




All times are GMT -7. The time now is 09:07 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008 The CEP Blog All Rights Reserved -Ad Management by RedTyger Visit The Global Fact Book

Content Relevant URLs by vBSEO 3.2.0