On 6/18/07, BradenM - Sonoma Computer wrote:
You can't just copy info from a book without understanding it enough
to fit your needs. The last sentence above appears to be a rule to
allow internal clients to connect to DNS servers on the Internet.
In your original post you say: "The commened line, rl1 traffic,
contains the pass rule for any DNS traffic,". And that line says:
pass in on rl1 proto { tcp, udp } from $dmz_block port 1024:65535 to any port 53
At a quick glance of your rules you aren't letting Internet traffic
resolve your IPs nor are you letting whatever this VR0 network is do
so either.
Greg
--
http://ticketmastersucks.org/tracker.html
Dethink to survive - Mclusky
| hooanon05 | [PATCH 67/67] merge aufs |
| Greg Kroah-Hartman | [PATCH 008/196] Chinese: add translation of volatile-considered-harmful.txt |
| monstr | [PATCH 33/52] [microblaze] bug headers files |
| Oliver Pinter | Re: x86: 4kstacks default |
git: | |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Gerrit Renker | [PATCH 15/37] dccp: Set per-connection CCIDs via socket options |
| David Miller | [GIT]: Networking |
| Natalie Protasevich | [BUG] New Kernel Bugs |
