Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 29 Dec 1998 12:45:19 -0800
From:      Ludwig Pummer <ludwigp@bigfoot.com>
To:        Dean <dean@thegrid.net>, freebsd-security@FreeBSD.ORG
Subject:   Re: ipfw and DNS
Message-ID:  <4.1.19981229124430.00a43cf0@mail-r>
In-Reply-To: <368933F6.CEB82066@thegrid.net>

next in thread | previous in thread | raw e-mail | index | archive | help
At 11:56 AM 12/29/98 , Dean wrote:
>Hello all,
>    I am setting up my first packet filtering gateway to protect a small
>lan from the Internet and I'd like to block everything that isn't
>necessary.  I am interested in hearing other people's input on how they
>get around the problem of getting DNS queries from the inside to the
>outside.  I'd rather not accept any old udp packet with a source port of
>53.  I have read Cheswick & Bellovin's Firewalls book and they offer a
>solution, but I am interested in hearing other solutions.
>    I am not subscribed to this mailing list (though I should be), so
>please include me in your replies.
>Thanks for your help,
>Dean

take a look at the different pre-written rule sets in /etc/rc.firewall, as
I believe they do the sort of stuff you want to do.

--Ludwig Pummer ( ludwigp@bigfoot.com )
ICQ UIN: 692441 (  ludwigp@email.com  )

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4.1.19981229124430.00a43cf0>