On Sun, Nov 15, 2020 at 10:50 PM J.Witvliet--- via users <
users(a)lists.fedoraproject.org> wrote:
*From: *"Jack Craig" <jack.craig.aptos(a)gmail.com>
*Date:* Saturday, 14 November 2020 at 21:11:39
*To: *"Community support for Fedora users"
<users(a)lists.fedoraproject.org>
*Subject:* Re: F32 bind9 split dns debug
is there an easier way to verify a port access to internal host besides
wireshark & tcpdump?
On Sat, Nov 14, 2020 at 11:51 AM Jack Craig <jack.craig.aptos(a)gmail.com>
wrote:
>
>
> On Sat, Nov 14, 2020 at 11:33 AM Jack Craig <jack.craig.aptos(a)gmail.com>
> wrote:
>
>>
>> this part looked ok to me, but i am not sure.
>>
>
> now seeing higher throughput, but still got...
>
> 14-Nov-2020 11:28:20.993 query-errors: info: client @0x7fc8601c9760
> 52.183.97.231#63450 (
linuxlighthouse.com): view external-wan-view: query
> failed (REFUSED) for
linuxlighthouse.com/IN/A at
> ../../../bin/named/query.c:7270
> 14-Nov-2020 11:28:21.030 query-errors: info: client @0x7fc8601c9760
> 20.190.57.96#61806 (
www.linuxlighthouse.com): view external-wan-view:
> query failed (REFUSED) for
www.linuxlighthouse.com/IN/A at
> ../../../bin/named/query.c:7270
> 14-Nov-2020 11:28:21.047 query-errors: info: client @0x7fc8601c9760
> 51.143.102.160#49893 (
www.linuxlighthouse.com): view external-wan-view:
> query failed (REFUSED) for
www.linuxlighthouse.com/IN/NS at
> ../../../bin/named/query.c:7270
>
> how can i see/test a query's processing between default.log &
> security.log ?
> i can see the query, if i could see why it's failing, i'd query this list
> less. ;)
>
> *www.linuxlighthouse.com/IN/NS <
http://www.linuxlighthouse.com/IN/NS> at
> ../../../bin/named/query.c:7270*
>
>
> *i looked at the query.c @7270 but was unable to gleen any useful
> insight. *
>
> *WRT networking, my block of static ip's is from
att.com <
http://att.com>*
>
> *i have cascaded routers from att's pace unit to a netgear night hawk
> that does*
> *port fwding for 53, 80 443 to the 10.0.0.101 sever.*
> *i use the firewall on the att rtr limiting to the above ports to pass
> through.*
>
> *the NH logs show connects to 53,80, & 443*
>
> *i also cranked debug to 10 in named logging, but so far,...*
>
>
> *lastly, as F32 comes w/iptables, i migrated to nftables. *
>
>
>>
>>
Dit bericht kan informatie bevatten die niet voor u is bestemd. Indien u
niet de geadresseerde bent of dit bericht abusievelijk aan u is
toegezonden, wordt u verzocht dat aan de afzender te melden en het bericht
te verwijderen. De Staat aanvaardt geen aansprakelijkheid voor schade, van
welke aard ook, die verband houdt met risico's verbonden aan het
elektronisch verzenden van berichten.
This message may contain information that is not intended for you. If you
are not the addressee or if this message was sent to you by mistake, you
are requested to inform the sender and delete the message. The State
accepts no liability for damage of any kind resulting from the risks
inherent in the electronic transmission of messages.
_______________________________________________
users mailing list -- users(a)lists.fedoraproject.org
To unsubscribe send an email to users-leave(a)lists.fedoraproject.org
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines:
https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedoraproject.org/archives/list/users@lists.fedoraproject.org