From owner-freebsd-stable Wed Dec 4 12:19: 2 2002 Delivered-To: freebsd-stable@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9BC8837B401 for ; Wed, 4 Dec 2002 12:19:00 -0800 (PST) Received: from mail1.thewrittenword.com (ns1.thewrittenword.com [67.89.104.183]) by mx1.FreeBSD.org (Postfix) with ESMTP id A662943ED1 for ; Wed, 4 Dec 2002 12:18:56 -0800 (PST) (envelope-from freebsd-stable@thewrittenword.com) Received: (from china@localhost) by mail1.thewrittenword.com (8.11.4/8.11.4) id gB4KIpp66363 for freebsd-stable@FreeBSD.ORG; Wed, 4 Dec 2002 14:18:51 -0600 (CST) (envelope-from freebsd-stable@thewrittenword.com) Date: Wed, 4 Dec 2002 14:18:51 -0600 From: Albert Chin To: freebsd-stable@FreeBSD.ORG Subject: Re: DNS query from public IP though localhost specified Message-ID: <20021204141851.B63349@oolong.il.thewrittenword.com> Reply-To: freebsd-stable@FreeBSD.ORG References: <20021204104103.F56412@oolong.il.thewrittenword.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: ; from 937863@primus.ca on Wed, Dec 04, 2002 at 02:46:44PM -0500 Sender: owner-freebsd-stable@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG On Wed, Dec 04, 2002 at 02:46:44PM -0500, Allan Jude wrote: > Connecting to any of your ips from your own box, will route through > localhost (netstat -rn) Yes. However, if I: $ ssh 192.168.0.1 then why should I see DNS queries from 67.89.x.y on 192.168.0.1? Maybe I should ask the ssh people as this seems to be ssh-specific. When I "ftp 192.168.0.1", I don't see any DNS queries on lo0 from 67.89.x.y. > -----Original Message----- > From: owner-freebsd-stable@FreeBSD.ORG > [mailto:owner-freebsd-stable@FreeBSD.ORG] On Behalf Of Albert Chin > Sent: Wednesday, December 04, 2002 11:41 AM > To: freebsd-stable@freebsd.org > Subject: DNS query from public IP though localhost specified > > > I have a multihomed FreeBSD 4.6-STABLE box with two public IPs on xl0 > and one private IP on xl1. The hostname corresponds to the private IP > on xl1. This box acts as a nameserver running BIND 9.2.1 and > /etc/resolv.conf is configured as: > search [internal domain] [external domain] > nameserver 127.0.0.1 > > If I try to ssh to this host from another box and have "tcpdump -i > lo0" running, I get tcpdump output indicating: > 18:16:48.342762 [public hostname].1572 > [public hostname].domain: > 19465+ PTR? [rev internal ip].in-addr.arpa. (43) > 18:16:48.343292 [public hostname].domain > [public hostname].1572: > 19465 Refused 0/0/0 (43) > 18:16:48.346175 localhost.[internal domain].1573 > localhost.[internal > domain].domain: 12661+ PTR? [rev internal ip].in-addr.arpa. (43) > 18:16:48.346555 localhost.[internal domain].domain > > localhost.[internal domain].1573: 12661* 1/1/1 PTR[|domain] > > It seems that only ssh causes this behaviour. ftpd causes only > localhost lookups. > > So, why am I seeing queries from the public IP on xl0 while listening > on lo0 > > -- > albert chin (china@thewrittenword.com) > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-stable" in the body of the message > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-stable" in the body of the message -- albert chin (china@thewrittenword.com) To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-stable" in the body of the message