Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 10 Oct 2001 07:08:54 -0400
From:      Louis LeBlanc <leblanc+freebsd@smtp.ne.mediaone.net>
To:        freebsd-questions@FreeBSD.org, freebsd-questions@FreeBSD.org
Subject:   Re: ipfw question - hostname/address spec?
Message-ID:  <20011010070853.A592@acadia.ne.mediaone.net>
In-Reply-To: <20011010001011.F387@blossom.cjclark.org>
References:  <20011004071834.A2458@acadia.ne.mediaone.net> <20011004135129.E297@blossom.cjclark.org> <20011009005629.D589@acadia.ne.mediaone.net> <20011009035651.N350@blossom.cjclark.org> <20011009145144.C64668@acadia.ne.mediaone.net> <20011010001011.F387@blossom.cjclark.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On 10/10/01 12:10 AM, Crist J. Clark sat at the `puter and typed:
> On Tue, Oct 09, 2001 at 02:51:45PM -0400, Louis LeBlanc wrote:
> > On 10/09/01 03:56 AM, Crist J. Clark sat at the `puter and typed:
> > > [snip]
> > > 
> > > /etc/rc.firewall would be good.
> > 
> > Ok, you asked for it . . .
> 
> [snip]
> 
> > > If DNS works fine once the system is up, but doesn't work when running
> > > the rc.firewall script, it sure sounds like you are killing your own
> > > lookups due to the rule ordering.
> > 
> > It doesn't work at all.  Not even via direct IP.
> 
> Hmmm?
> 
> > Thanks for your help.  I'm sure to learn something useful in all this.
> > Which is the point, I guess.
> 
> [snip]
> 
> I can't reproduce the problem and it does look like DNS lookups should
> be working by the time the SMTP and NNTP rules are reached. I'm not
> sure what is happening here. You could try adding some logging to see
> what is going on in the ruleset. It also may be some other strange DNS
> interaction.

I found the DNS culprit.  Looks like I need to try that firewall
again.  Turns out I had borrowed a bogus dhclient-enter-hooks script
that was hosing resolv.conf.  DNS seens to be solved for now.

Thanks!

I'll try that firewall again and let you know if it still hoses
things.

BTW, in Linux, it was fairly trivial to release a DHCP lease, renew
it, reset the firewall and get masquerading back up (automatic the way
Linux did masquerading thru the firewall) - all without a reboot.  Is
there a relatively painless way to do this in FreeBSD?

Thanks for your help!

Lou
-- 
Louis LeBlanc       leblanc@acadia.ne.mediaone.net
Fully Funded Hobbyist, KeySlapper Extrordinaire :)
http://acadia.ne.mediaone.net                 ԿԬ

Turnaucka's Law:
  The attention span of a computer is only as long as its electrical cord.


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20011010070853.A592>