Re: DNS and PF

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: OpenBSD <misc@...>
Date: Monday, June 18, 2007 - 6:49 pm

On 6/18/07, BradenM - Sonoma Computer wrote:

You can't just copy info from a book without understanding it enough
to fit your needs. The last sentence above appears to be a rule to
allow internal clients to connect to DNS servers on the Internet.

In your original post you say: "The commened line, rl1 traffic,
contains the pass rule for any DNS traffic,". And that line says:

pass in on rl1 proto { tcp, udp } from $dmz_block port 1024:65535 to any port 53

At a quick glance of your rules you aren't letting Internet traffic
resolve your IPs nor are you letting whatever this VR0 network is do
so either.

Greg
--
http://ticketmastersucks.org/tracker.html

Dethink to survive - Mclusky

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: DNS and PF, BradenM - Sonoma Computer..., (Mon Jun 18, 6:01 pm)
Re: DNS and PF, Greg Thomas, (Mon Jun 18, 6:49 pm)