<div>Thanks Marc, this worked. </div>
<div> </div>
<div>Now I need to setup acl sets for the internal and external network.</div>
<div> </div>
<div> </div>
<div class="gmail_quote">On Thu, Jul 3, 2008 at 10:46 AM, Marc Skinner <<a href="mailto:marc@e-skinner.net">marc@e-skinner.net</a>> wrote:<br>
<blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">Might want to try this:<br><br>acl bogusnets { <a href="http://0.0.0.0/8" target="_blank">0.0.0.0/8</a>;<br>
<a href="http://169.254.0.0/16" target="_blank">169.254.0.0/16</a>;<br> <a href="http://224.0.0.0/3" target="_blank">224.0.0.0/3</a>;<br>};<br><br>acl internalnet {<br> <a href="http://127.0.0.1/" target="_blank">127.0.0.1</a>;<br>
<a href="http://192.168.1.0/24" target="_blank">192.168.1.0/24</a>;<br> };<br><br>acl mynet {<br> <a href="http://127.0.0.1/" target="_blank">127.0.0.1</a>;<br> <a href="http://192.168.1.0/24" target="_blank">192.168.1.0/24</a>;<br>
};<br><br>acl thisdns {<br> <a href="http://127.0.0.1/" target="_blank">127.0.0.1</a>;<br> 192.168.1.whaever your DNS server is;<br> };<br><br><br><br>in options section:<br><br><br> allow-notify {<br>
mynet;<br> };<br> allow-query {<br> mynet;<br> };<br> allow-recursion {<br> mynet;<br> };<br> blackhole {<br> bogusnets;<br> };<br> listen-on {<br>
thisdns;<br> };<br> listen-on-v6 {<br> none;<br> };<br> query-source address * port 53;<br> version "!BIND!";<br><br><br><br><br><br><br><br><br><br><br>James wrote:<br>
<blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">
<div class="Ih2E3d">Howdy,<br> I have Fedora 9 installed and would like to use it as the DNS system in the house.<br> The setup is as follows<br> options {<br></div> listen-on port 53 { <a href="http://127.0.0.1/" target="_blank">127.0.0.1</a> <<a href="http://127.0.0.1/" target="_blank">http://127.0.0.1</a>>; };
<div class="Ih2E3d"><br> listen-on-v6 port 53 { ::1; };<br> directory "/var/named";<br> dump-file "/var/named/data/cache_dump.db";<br> statistics-file "/var/named/data/named_stats.txt";<br>
memstatistics-file "/var/named/data/named_mem_stats.txt";<br> allow-query { localhost; };<br> recursion yes;<br> forwarders {<br></div> <a href="http://68.87.77.130/" target="_blank">68.87.77.130</a> <<a href="http://68.87.77.130/" target="_blank">http://68.87.77.130</a>>;<br>
<a href="http://68.87.72.130/" target="_blank">68.87.72.130</a> <<a href="http://68.87.72.130/" target="_blank">http://68.87.72.130</a>>;
<div class="Ih2E3d"><br> };<br>};<br>logging {<br> channel default_debug {<br> file "data/named.run";<br> severity dynamic;<br> };<br>};<br>zone "." IN {<br>
type hint;<br></div> file "<a href="http://named.ca/" target="_blank">named.ca</a> <<a href="http://named.ca/" target="_blank">http://named.ca</a>>";
<div class="Ih2E3d"><br>};<br><br>include "/etc/named.rfc1912.zones";<br> zone "home.local" {<br> type master;<br> file "/var/named/home.local.hosts";<br> };<br><br>zone "1.168.192.in-addr.arpa" {<br>
type master;<br> file "1.168.192.in-addr.arpa.zone";<br> allow-update { key "rndckey"; };<br> notify yes;<br> I have the files in /var/named setup and configured. From the DNS system I can type<br>
nslookup 43p and get the following<br>[root@fc9 named]# vi /etc/named.conf<br>[root@fc9 named]# nslookup 43p<br></div>Server: <a href="http://127.0.0.1/" target="_blank">127.0.0.1</a> <<a href="http://127.0.0.1/" target="_blank">http://127.0.0.1</a>><br>
Address: <a href="http://127.0.0.1/#53" target="_blank">127.0.0.1#53</a> <<a href="http://127.0.0.1/#53" target="_blank">http://127.0.0.1#53</a>><br>Name: 43p.home.local<br>Address: <a href="http://192.168.1.52/" target="_blank">192.168.1.52</a> <<a href="http://192.168.1.52/" target="_blank">http://192.168.1.52</a>>
<div class="Ih2E3d"><br> From a windows system I get the following<br>C:\Users\dalan>nslookup 43p<br>Server: UnKnown<br></div>Address: <a href="http://192.168.1.50:53/" target="_blank">192.168.1.50:53</a> <<a href="http://192.168.1.50:53/" target="_blank">http://192.168.1.50:53</a>>
<div class="Ih2E3d"><br>*** UnKnown can't find 43p: Query refused<br> From the AIX system I get<br>(43p-aix) [dalan] nslookup 43p<br>*** Can't find server name for address 192.168.1.50:Query refused<br>*** Default servers are not available<br>
(43p-aix) [dalan]<br>I have shut off the firewall and SE-Linux on the Fedora system. I'm not sure why the fedora system is blocking/refusing the request coming from another system.<br>I even put the following entries in iptables.<br>
</div>SERVER_IP="<a href="http://192.168.1.50/" target="_blank">192.168.1.50</a> <<a href="http://192.168.1.50/" target="_blank">http://192.168.1.50</a>>"
<div class="Ih2E3d"><br>iptables -A INPUT -p udp -s 0/0 --sport 1024:65535 -d $SERVER_IP --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT<br>iptables -A OUTPUT -p udp -s $SERVER_IP --sport 53 -d 0/0 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT<br>
iptables -A INPUT -p udp -s 0/0 --sport 53 -d $SERVER_IP --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT<br>iptables -A OUTPUT -p udp -s $SERVER_IP --sport 53 -d 0/0 --dport 53 -m state --state ESTABLISHED -j ACCEPT<br>
iptables -A INPUT -p tcp -s 0/0 --sport 1024:65535 -d $SERVER_IP --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT<br>iptables -A OUTPUT -p tcp -s $SERVER_IP --sport 53 -d 0/0 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT<br>
iptables -A INPUT -p tcp -s 0/0 --sport 53 -d $SERVER_IP --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT<br>iptables -A OUTPUT -p tcp -s $SERVER_IP --sport 53 -d 0/0 --dport 53 -m state --state ESTABLISHED -j ACCEPT<br>
I still have the same effect.<br> Running the following shows that the system is refusing the connection.<br>/usr/sbin/tcpdump -X port 53<br><br>[root@fc9 named]# /usr/sbin/tcpdump -X port 53<br>tcpdump: verbose output suppressed, use -v or -vv for full protocol decode<br>
listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes<br>21:39:38.512926 IP aix.sparish.local.52686 > fc9.sparish.local.domain: 46304+ PTR? 50.1.168.192.in-addr.arpa. (43)<br> 0x0000: 4500 0047 ac22 0000 1e11 6ccd c0a8 0134 E..G."....l....4<br>
0x0010: c0a8 0132 cdce 0035 0033 7c2c b4e0 0100 ...2...5.3|,....<br> 0x0020: 0001 0000 0000 0000 0235 3001 3103 3136 .........50.1.16<br></div> 0x0030: 3803 3139 3207 696e 2d61 6464 7204 6172 <a href="http://8.192.in-addr.ar/" target="_blank">8.192.in-addr.ar</a> <<a href="http://8.192.in-addr.ar/" target="_blank">http://8.192.in-addr.ar</a>>
<div class="Ih2E3d"><br> 0x0040: 7061 0000 0c00 01 pa.....<br>21:39:38.519048 IP fc9.sparish.local.domain > aix.sparish.local.52686: 46304 Refused- 0/0/0 (43)<br></div> 0x0000: 4500 0047 0000 4000 4011 b6ef c0a8 0132 E..G..@.@......2 <mailto:<a href="mailto:E..G..@" target="_blank">E..G..@</a>.@......2>
<div class="Ih2E3d"><br> 0x0010: c0a8 0134 0035 cdce 0033 fc26 b4e0 8105 ...4.5...3.&....<br> 0x0020: 0001 0000 0000 0000 0235 3001 3103 3136 .........50.1.16<br></div> 0x0030: 3803 3139 3207 696e 2d61 6464 7204 6172 <a href="http://8.192.in-addr.ar/" target="_blank">8.192.in-addr.ar</a> <<a href="http://8.192.in-addr.ar/" target="_blank">http://8.192.in-addr.ar</a>>
<div class="Ih2E3d"><br> 0x0040: 7061 0000 0c00 01 pa.....<br> Any help would be welcome<br> Thanks<br></div>------------------------------------------------------------------------
<div class="Ih2E3d"><br><br>_______________________________________________<br>TCLUG Mailing List - Minneapolis/St. Paul, Minnesota<br><a href="mailto:tclug-list@mn-linux.org" target="_blank">tclug-list@mn-linux.org</a><br>
<a href="http://mailman.mn-linux.org/mailman/listinfo/tclug-list" target="_blank">http://mailman.mn-linux.org/mailman/listinfo/tclug-list</a><br> <br></div></blockquote><br></blockquote></div><br>