Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 29 Feb 2016 03:09:17 -0500 (EST)
From:      "Dumitru" <statdata2015@gmail.com>
To:        freebsd-questions@freebsd.org
Subject:   Import Statistics and Analytics for Russian, Ukrainian and Kazakhstan Markets
Message-ID:  <20160229080917.DA5728BC0A@pmta4-1-07>

next in thread | raw e-mail | index | archive | help
Unsubscribe from this mailing list: http://link.citrusemail.com/u/443/fc=
d12c71affc8955aacae2a21ae20eb5ca5f1aa49e5edb96

Suite 2, 5 St. Vincent Street, Edinburgh, EH3 6SW, United Kingdom
From owner-freebsd-questions@freebsd.org  Mon Feb 29 17:57:10 2016
Return-Path: <owner-freebsd-questions@freebsd.org>
Delivered-To: freebsd-questions@mailman.ysv.freebsd.org
Received: from mx1.freebsd.org (mx1.freebsd.org
 [IPv6:2001:1900:2254:206a::19:1])
 by mailman.ysv.freebsd.org (Postfix) with ESMTP id 99717AB89AC
 for <freebsd-questions@mailman.ysv.freebsd.org>;
 Mon, 29 Feb 2016 17:57:10 +0000 (UTC)
 (envelope-from sergeig.public@gmail.com)
Received: from mail-vk0-x22f.google.com (mail-vk0-x22f.google.com
 [IPv6:2607:f8b0:400c:c05::22f])
 (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
 (Client CN "smtp.gmail.com",
 Issuer "Google Internet Authority G2" (verified OK))
 by mx1.freebsd.org (Postfix) with ESMTPS id 556C5341
 for <freebsd-questions@freebsd.org>; Mon, 29 Feb 2016 17:57:10 +0000 (UTC)
 (envelope-from sergeig.public@gmail.com)
Received: by mail-vk0-x22f.google.com with SMTP id e6so141812935vkh.2
 for <freebsd-questions@freebsd.org>; Mon, 29 Feb 2016 09:57:10 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;
 h=mime-version:date:message-id:subject:from:to;
 bh=x1mIi4tOUr4/Gpcba50tIzQ70tRKhJfPW+rCbJp4Ol0=;
 b=XnioFUuFfhk/AlgLw40VeQUoCNYhj07sloub+YmeSZS2+1/pM0yx2AY2efU+ofGjl9
 FdmsmSDwj2EXqBNW/RfwkZa9tnPaBYygzT3hWcMBrgfB09hhk8QeO8SGThPDwfF+cUM2
 bA8h3IIbwocHQDyZdupvzNZY/czp32sFC1NspB76kfcBrBPKcb2HWAZkMhhFKb6XBPhV
 QkbI5XTATw+YfQR9tDHZO60qD+T17hRo+JbsBrlvUl/zsXEj29TlMFtc3Zf8xa5H+Sjv
 PpSI/I9R8LJ4wloWII97JKS4HRWxwpWJnQpMueB/FlrjDJiwR5KjAf4Z/kMYyqSb6wGy
 Mvzg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20130820;
 h=x-gm-message-state:mime-version:date:message-id:subject:from:to;
 bh=x1mIi4tOUr4/Gpcba50tIzQ70tRKhJfPW+rCbJp4Ol0=;
 b=dJvMBFH97SvQJYuKPUDVXEwPA8RJRfHZWlzG+/bFxdplv4Uxh68mLicE/av+iBdsC1
 rxgaxIFQNTJJf2NZ1ULPMqBAu+e2OuRc+HTZiOUqizMV5XEFmkUwxZygpKHgaU/vaT3v
 HzJLjqweO7y3VxLXHbxPu28fdZtLp4hBEl2RNBMWL4wGRuzCQqwz842j/necdbBiKmlU
 alxTCeN213L7n8gsOGTap7l6Zmg6Jl0I0Gp2685ud0fIsB8k/13hfpziLmd68r+CVASE
 Z4c3pOQmucnpC1rgblU5uh8f3IjEB8Vqe5+HcmtmdUoHeeDXdNmcZ1jHJs7r8zR8facV
 igUQ==
X-Gm-Message-State: AD7BkJKJX3RmARwWQeCXZAXtey2OdkjQln8EoXTwIXQO0wndkIdX64ZK6mqUEQIprHVPm3hQojm72LRff+9mjg==
MIME-Version: 1.0
X-Received: by 10.31.54.80 with SMTP id d77mr10925649vka.138.1456768629355;
 Mon, 29 Feb 2016 09:57:09 -0800 (PST)
Received: by 10.31.174.132 with HTTP; Mon, 29 Feb 2016 09:57:09 -0800 (PST)
Date: Mon, 29 Feb 2016 09:57:09 -0800
Message-ID: <CAFLLzCMntj4X2vLWd1VG=heE5S5sNVFsiSPNqyc8MAwPiWbMOw@mail.gmail.com>
Subject: DNS with host works, but not with mysql or ping
From: Sergei G <sergeig.public@gmail.com>
To: FreeBSD Questions <freebsd-questions@freebsd.org>
Content-Type: text/plain; charset=UTF-8
X-Content-Filtered-By: Mailman/MimeDel 2.1.20
X-BeenThere: freebsd-questions@freebsd.org
X-Mailman-Version: 2.1.20
Precedence: list
List-Id: User questions <freebsd-questions.freebsd.org>
List-Unsubscribe: <https://lists.freebsd.org/mailman/options/freebsd-questions>, 
 <mailto:freebsd-questions-request@freebsd.org?subject=unsubscribe>
List-Archive: <http://lists.freebsd.org/pipermail/freebsd-questions/>;
List-Post: <mailto:freebsd-questions@freebsd.org>
List-Help: <mailto:freebsd-questions-request@freebsd.org?subject=help>
List-Subscribe: <https://lists.freebsd.org/mailman/listinfo/freebsd-questions>, 
 <mailto:freebsd-questions-request@freebsd.org?subject=subscribe>
X-List-Received-Date: Mon, 29 Feb 2016 17:57:10 -0000

If I use host command to resolve name to IP, then I get a correct IP.

If I use ping, mysql, fetch commands, then DNS fails to resolve.  I can't
quite figure out what the difference is.

Jailed machine configuration:

1) issue is inside jailed system
2) /etc/resolv.conf points to host's machine with nameserver 10.0.1.10

Host machine:
1) runs firewall
2) runs local_unbind on all 53 ports
3) runs nsd for private network on 1053 port.

I am quite confused ATM.

pfctl -sr   Output on the host:

No ALTQ support in kernel
ALTQ related functions disabled
scrub in all fragment reassemble
block drop in log on bce0 all
block return in log on bce0 proto tcp from any to any port = ssh
block drop in log (to pflog1) quick on bce0 proto tcp from any to any port
= mdns
block drop in log (to pflog1) quick on bce0 proto tcp from any to any port
= 17500
block drop in log (to pflog1) quick on bce0 proto udp from any to any port
= mdns
block drop in log (to pflog1) quick on bce0 proto udp from any to any port
= 17500
block drop in quick on bce0 proto udp from any to any port = netbios-ns
block drop in quick on bce0 proto udp from any to any port = netbios-dgm
block drop in quick on bce0 proto udp from any to any port = 1900
block drop in quick on bce0 proto udp from any to any port = sunrpc
block drop in quick on bce0 proto tcp from any to any port = commplex-main
block drop in log (to pflog1) quick on bce0 proto igmp all
block drop in quick on bce0 inet proto udp from 0.0.0.0 port = bootpc to
any port = bootps
pass in quick on bce0 inet proto udp from 10.0.1.1 port = bootps to any
port = bootpc keep state
pass out quick on bce0 inet proto udp from any port = bootpc to 10.0.1.1
port = bootps keep state
block drop in log (to pflog1) quick on bce0 inet6 all
pass in quick on bce0 inet proto tcp from 10.0.1.0/24 to 10.0.1.10 port =
domain flags S/SA keep state
pass in quick on bce0 inet proto tcp from 10.0.1.0/24 to 10.0.1.10 port =
ssh flags S/SA keep state
pass in quick on bce0 inet proto tcp from 192.168.3.0/24 to 10.0.1.10 port
= domain flags S/SA keep state
pass in quick on bce0 inet proto tcp from any to 10.0.1.10 port = http
flags S/SA keep state
pass in quick on bce0 inet proto tcp from any to 10.0.1.10 port = https
flags S/SA keep state
pass in quick on bce0 inet proto tcp from any to 10.0.1.10 port = auth
flags S/SA keep state
pass in quick on bce0 inet proto tcp from 198.182.9.1 to 10.0.1.10 port =
ssh flags S/SA keep state
pass in quick on bce0 inet proto tcp from 10.0.1.101 port = 8090 to
10.0.1.10 flags S/SA keep state
pass in quick on bce0 inet proto udp from 10.0.1.0/24 to 10.0.1.10 port =
domain keep state
pass in quick on bce0 inet proto udp from 192.168.3.0/24 to 10.0.1.10 port
= domain keep state
pass in quick on bce0 inet proto icmp from 10.0.1.0/24 to 10.0.1.10
icmp-type echoreq keep state
pass in log quick on bce0 inet proto tcp from 10.0.1.0/24 to 10.0.1.10 port
= domain flags S/SA keep state
pass in log quick on bce0 inet proto tcp from 10.0.1.0/24 to 10.0.1.10 port
= 1053 flags S/SA keep state
pass in log quick on bce0 inet proto udp from 10.0.1.0/24 to 10.0.1.10 port
= domain keep state
pass in log quick on bce0 inet proto udp from 10.0.1.0/24 to 10.0.1.10 port
= 1053 keep state
pass in log quick on lo0 inet proto tcp from 10.0.1.0/24 to 127.0.0.1 port
= 1053 flags S/SA keep state
pass in log quick on lo0 inet proto udp from 10.0.1.0/24 to 127.0.0.1 port
= 1053 keep state
pass in quick on bce0 inet proto tcp from 10.0.1.0/24 to 192.168.3.17 port
= imap flags S/SA keep state
pass in quick on bce0 inet proto tcp from 10.0.1.0/24 to 192.168.3.17 port
= smtp flags S/SA keep state
pass in quick on bce0 inet proto tcp from 10.0.1.0/24 to 192.168.3.17 port
= submission flags S/SA keep state
pass in quick on bce0 inet proto tcp from 192.168.3.0/24 to 192.168.3.17
port = imap flags S/SA keep state
pass in quick on bce0 inet proto tcp from 192.168.3.0/24 to 192.168.3.17
port = smtp flags S/SA keep state
pass in quick on bce0 inet proto tcp from 192.168.3.0/24 to 192.168.3.17
port = submission flags S/SA keep state
pass in quick on bce0 inet proto tcp from 10.0.1.10 to 192.168.3.11 port =
9000 flags S/SA keep state
pass in quick on bce0 inet proto tcp from 10.0.1.10 to 192.168.3.15 port =
9000 flags S/SA keep state
pass in quick on bce0 inet proto tcp from 10.0.1.10 to 192.168.3.22 port =
9000 flags S/SA keep state
pass in quick on bce0 inet proto tcp from 10.0.1.10 to 192.168.3.13 port =
9001 flags S/SA keep state
pass out quick on bce0 inet proto tcp from 10.0.1.10 to 10.0.1.101 port =
8090 flags S/SA keep state
pass out quick on bce0 inet proto udp from any to any port = domain keep
state
pass out quick on bce0 inet proto icmp all icmp-type echoreq keep state
pass in on bce0 inet proto tcp from 10.0.1.0/24 to any port = ftp flags
S/SA keep state
pass in on bce0 inet proto tcp from 10.0.1.0/24 to any port > 49151 flags
S/SA keep state



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20160229080917.DA5728BC0A>