[H-GEN] local dns only

Douglas C chexsum at optusnet.com.au
Thu Dec 5 07:45:22 EST 2002


[ Humbug *General* list - semi-serious discussions about Humbug and     ]
[ Unix-related topics. Posts from non-subscribed addresses will vanish. ]

> On Thu Dec 05 2002 at 18:47, Tony Nugent wrote:
>
> > The easiest way perhaps is to firewall the port...
> >
> >   iptables -I INPUT -p tcp --syn --dport 53 -j DROP
> >   iptables -I INPUT -p udp --dport 53 -m state --state NEW -j DROP
> >
> > (or similar rules that do the same thing)

Its a good idea to also block traffic which doesnt come from the nameservers
that are being used *I should practise what I preach first too*.


---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.423 / Virus Database: 238 - Release Date: 11/25/02


--
* This is list (humbug) general handled by majordomo at lists.humbug.org.au .
* Postings to this list are only accepted from subscribed addresses of
* lists 'general' or 'general-post'.  See http://www.humbug.org.au/



More information about the General mailing list