From owner-freebsd-questions Tue Jul 23 5:58:29 2002 Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id CA39D37B400 for ; Tue, 23 Jul 2002 05:58:07 -0700 (PDT) Received: from mail1.ing.nl (mail1.ing.nl [145.221.93.2]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8A4A243E4A for ; Tue, 23 Jul 2002 05:58:06 -0700 (PDT) (envelope-from Danny.Carroll@mail.ing.nl) X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4910.0300 content-class: urn:content-classes:message MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----_=_NextPart_001_01C23248.89FF0B9F" Subject: RE: Need help with DNS Date: Tue, 23 Jul 2002 14:57:45 +0200 Content-Transfer-Encoding: 7bit Message-ID: <6C506EA550443D44A061432F1E92EA4C6C5381@ing.com> X-MS-Has-Attach: X-MS-TNEF-Correlator: Thread-Topic: Need help with DNS Thread-Index: AcIyR3jwJN/HBqS0RcS553c/pnyy5AAAPYPQ From: "Carroll, D. (Danny)" To: , "sagacious" Cc: "FBSDQ" Importance: normal X-OriginalArrivalTime: 23 Jul 2002 12:57:45.0657 (UTC) FILETIME=[8A25EA90:01C23248] Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG This is a multi-part message in MIME format. ------_=_NextPart_001_01C23248.89FF0B9F Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Why don't you just add the names you want to the host files of the machines on your internal network? -D -----Original Message----- From: Joe & Fhe Barbish [mailto:barbish@a1poweruser.com] Sent: Tuesday, July 23, 2002 2:49 PM To: sagacious Cc: FBSDQ Subject: RE: Need help with DNS Restating your problem. Every thing works as expected for requests originating from the public internet, But any requests origination from the LAN behind your firewall gets denied. This could very well be a IPFW firewall rules problem. You have to have a IPFW rule to allow all originating LAN traffic to pass through the firewall. For each LAN Nic card you have on your GATEWAY/IPFW FBSD box, you must have an corresponding rule in the IPFW rules file like this. =20 allow all from any to any via xl0 Where xl0 is the FBSD NIC card device name of your Lan Nic card. This rule normally is located in the beginning of the IPFW rules file. If you still need help post your IPFW rules file for review. =20 Joe =20 -----Original Message----- From: owner-freebsd-questions@FreeBSD.ORG [mailto:owner-freebsd-questions@FreeBSD.ORG]On Behalf Of sagacious Sent: Tuesday, July 23, 2002 3:21 AM To: freebsd-questions@freebsd.org Subject: Need help with DNS =20 Hi. I changed my network setup a while ago. I had to put everything behind a firewall router due to a denial of service attack.. So now, I am specifying a "static" ip in my rc.conf, but it's a local one, 192.168.1.20, I port forwarded all the services to that ip. The problem is, you can all go to my site, http://www.unixhideout.com , but if I click that url, my router pass box pops up... I had to temporarily change ALL the links in my site, for example to I don't want to have to do this, and a lot of things do not work for me and its my site!! Well, I posted this a while ago, and a lot of people said if I ran my own DNS for my domain, I could stop this from happening.. Well I took the time to learn DNS a bit, and im running it now, and I was wondering exactly what I need to do.. In my unixhideout.com.hosts I specified this.. =20 $ttl 38400 unixhideout.com. IN SOA labs. root.unixhideout.com. ( 1025839968 10800 3600 604800 38400 ) unixhideout.com. IN NS labs labs.unixhideout.com. IN A 65.187.193.189 root.unixhideout.com. IN RP root.unixhideout.com. admin Host-Info.unixhideout.com. IN HINFO INTEL FreeBSD mail.unixhideout.com. IN MX 10 65.187.193.189 unixhideout.com. IN A 65.187.193.189 mail.unixhideout.com. IN A 65.187.193.189 smtp.unixhideout.com. IN A 65.187.193.189 www.unixhideout.com. IN A 65.187.193.189 pop3.unixhideout.com. IN A 65.187.193.189 irc.unixhideout.com. IN A 65.187.193.189 email.unixhideout.com. IN A 65.187.193.189 ftp.unixhideout.com. IN A 65.187.193.189 =20 Everything works.. You guys (the net) can go to my site and use all the services. But I cannot.. I tried changing all those IPS to 192.168.1.20, and then I could use unixhideout.com and you couldn't!! im losing my patience! Please tell me what I have to do for the internet AND ME to be able to use the domain I paid for! =3D] and when you explain pretend I'm = 2 years old. Im fragile. Thanks! =20 sagacious (Mike) Network administrator The unixhideout network http://www.unixhideout.com =20 -----------------------------------------------------------------=0A= ATTENTION:=0A= The information in this electronic mail message is private and=0A= confidential, and only intended for the addressee. Should you=0A= receive this message by mistake, you are hereby notified that=0A= any disclosure, reproduction, distribution or use of this=0A= message is strictly prohibited. Please inform the sender by=0A= reply transmission and delete the message without copying or=0A= opening it.=0A= =0A= Messages and attachments are scanned for all viruses known.=0A= If this message contains password-protected attachments, the=0A= files have NOT been scanned for viruses by the ING mail domain.=0A= Always scan attachments before opening them.=0A= ----------------------------------------------------------------- ------_=_NextPart_001_01C23248.89FF0B9F Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Why=20 don't you just add the names you want to the host files of the machines = on your=20 internal network?
-D
-----Original Message-----
From: Joe & Fhe = Barbish=20 [mailto:barbish@a1poweruser.com]
Sent: Tuesday, July 23, = 2002 2:49=20 PM
To: sagacious
Cc: FBSDQ
Subject: RE: = Need=20 help with DNS

Restating=20 your problem. Every thing works as expected for requests originating = from the=20 public internet, But any requests origination from the LAN behind your = firewall gets denied.  = This could=20 very well be a IPFW firewall rules problem. You have to have a IPFW = rule to=20 allow all originating LAN traffic to pass through the firewall. For = each LAN=20 Nic card you have on your GATEWAY/IPFW FBSD box, you must have an=20 corresponding rule in the IPFW rules file like this.   

allow=20 all from any to any via xl0   =20 Where xl0 is the FBSD NIC card device name of your Lan Nic = card.  This rule normally is = located in the=20 beginning of the IPFW rules file. If you still need help post your = IPFW rules=20 file for review.

 

Joe

 

-----Original=20 Message-----
From:=20 owner-freebsd-questions@FreeBSD.ORG=20 [mailto:owner-freebsd-questions@FreeBSD.ORG]On Behalf Of = sagacious
Sent: Tuesday, July 23, 2002 = 3:21=20 AM
To:=20 freebsd-questions@freebsd.org
Subject: Need help with=20 DNS

 

Hi. I=20 changed my network setup a while ago. I had to put everything behind a = firewall router due to a denial of service attack.. So now, I am = specifying a=20 “static” ip in my rc.conf, but it’s a local one, = 192.168.1.20, I port=20 forwarded all the services to that ip. The problem is, you can all go = to my=20 site, http://www.unixhideout.com,=20 but if I click that url, my router pass box pops up… I had to = temporarily=20 change ALL the links in my site, for example <img src=3Dh= ttp://www.unixhideout.com/img/blah.gif=20 to <img src=3D/img/blah.gif.. and I access the box using http://192.168.1.20 I don’t = want to have to do=20 this, and a lot of things do not work for me and its my site!! Well, I = posted=20 this a while ago, and a lot of people said if I ran my own DNS for my = domain,=20 I could stop this from happening.. Well I took the time to learn DNS a = bit,=20 and im running it now, and I was wondering exactly what I need to do.. = In my=20 unixhideout.com.hosts I specified this..

 

$ttl=20 38400

unixhideout.com.        = IN     =20 SOA    =20 labs. root.unixhideout.com. (

           &n= bsp;           =20 1025839968

           &n= bsp;           =20 10800

           &n= bsp; =20           3= 600

           &n= bsp;           =20 604800

           &n= bsp;           =20 38400 )

unixhideout.com.        = IN     =20 NS     =20 labs

labs.unixhideout.com.   IN      = A      =20 65.187.193.189

root.unixhideout.com.   IN      = RP     =20 root.unixhideout.com. admin

Host-Info.unixhideout.com.      = IN      = HINFO   INTEL=20 FreeBSD

mail.unixhideout.com.   IN      = MX      10=20 65.187.193.189

unixhideout.com.        = IN     =20 A      =20 65.187.193.189

mail.unixhideout.com.   IN      = A      =20 65.187.193.189

smtp.unixhideout.com.   IN      = A       65.187.193.189

www.unixhideout.com.    IN      = A      =20 65.187.193.189

pop3.unixhideout.com.   IN      = A      =20 65.187.193.189

irc.unixhideout.com.    IN      = A      =20 65.187.193.189

email.unixhideout.com.  IN      = A      =20 65.187.193.189

ftp.unixhideout.com.    IN      = A      =20 65.187.193.189

 

Everything=20 works.. You guys (the net) can go to my site and use all the services. = But I=20 cannot.. I tried changing all those IPS to 192.168.1.20, and then I = could use=20 unixhideout.com and you couldn’t!! im losing my patience! Please = tell me what=20 I have to do for the internet AND ME to be able to use the domain I = paid for!=20 =3D] and when you explain pretend I’m 2 years old. Im fragile.=20 Thanks!

 

sagacious=20 (Mike)

Network=20 administrator

The=20 unixhideout network

http://www.unixhideout.com=

 

-------------------------------------------------------------= ----
ATTENTION:
The information in this electronic mail message is = private and
confidential, and only intended for the addressee. Should = you
receive this message by mistake, you are hereby notified = that
any disclosure, reproduction, distribution or use of = this
message is strictly prohibited. Please inform the sender = by
reply transmission and delete the message without copying = or
opening it.

Messages and attachments are scanned for all = viruses known.
If this message contains password-protected = attachments, the
files have NOT been scanned for viruses by the ING = mail domain.
Always scan attachments before opening = them.
----------------------------------------------------------------= - ------_=_NextPart_001_01C23248.89FF0B9F-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message