iptables is like alchemy

Jorge Fábregas jorge.fabregas at gmail.com
Thu Jan 3 02:13:24 UTC 2013


On 01/02/2013 07:54 PM, Alan Evans wrote:
> DNS queries (portal is also a DNS server) to the external
> interface stop working.

Hi,

Please elaborate more.  Why does 192.168.0.35 perform DNS queries
against the "external interface" of the firewall? Why not use the
internal ip?   If you manually perform dig @192.168.0.1 google.com  (I
assume that's your firewall ip) from 192.168.0.35, does it work?   Did
you create the corresponding MASQUERADE rule (under POSTROUTING) for the
egress traffic coming from 192.168.0.35?  I believe so , otherwise you
wouldn't have been able to connect from the outside to 20022.

Please post your rules if you want more detailed help.  I really don't
see any relationship with what you describe & DNS problems.

--
Jorge


More information about the users mailing list