From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: From: =?koi8-r?B?8MHXxcwg58zVyM/Xw8XX?= To: Date: Wed, 15 Jan 2003 18:06:38 +0500 Message-ID: <000001c2bc96$f090c150$1a010a0a@vep.local> MIME-Version: 1.0 Content-Type: text/plain; charset="koi8-r" Content-Transfer-Encoding: quoted-printable X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook, Build 10.0.4024 Importance: Normal X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106 Subject: [Comm] Caching nameserver & ipchains Sender: community-admin@altlinux.ru Errors-To: community-admin@altlinux.ru X-BeenThere: community@altlinux.ru X-Mailman-Version: 2.0.9 Precedence: bulk Reply-To: community@altlinux.ru List-Unsubscribe: , List-Id: List-Post: List-Help: List-Subscribe: , List-Archive: Archived-At: List-Archive: List-Post: =FA=C4=D2=C1=D7=D3=D4=D7=D5=CA=D4=C5. =F5=D3=D4=C1=CE=CF=D7=CC=C5=CE =CB=DC=DB=C9=D2=D5=C0=DD=C9=CA nameserver = (caching-nameserver-7.0-ipl2mdk =C9 bind-8.2.3-ipl4mdk) =C9 =D0=D2=CF=D0=C9=D3=C1=CE=D9 = =D3=CC=C5=C4=D5=C0=DD=C9=C5 =D0=D2=C1=D7=C9=CC=C1 ipchains -A input -i $EXTERNAL_INTERFACE -p udp -s $NAMESERVER_1 53 -d $IPADDR 53 -j ACCEPT ipchains -A output -i $EXTERNAL_INTERFACE -p udp -s $IPADDR 53 -d $NAMESERVER_1 53 -j ACCEPT ipchains -A input -i $EXTERNAL_INTERFACE -p udp -s $NAMESERVER_2 53 -d $IPADDR 53 -j ACCEPT ipchains -A output -i $EXTERNAL_INTERFACE -p udp -s $IPADDR 53 -d $NAMESERVER_2 53 -j ACCEPT =EE=CF =CE=C5 =D2=C1=C2=CF=D4=C1=C5=D4.=20 =F7 named.conf =C5=D3=D4=D8 =D3=CC=C5=C4=D5=C0=DD=C9=CA = =CB=CF=CD=CD=C5=CE=D4=C1=D2=C9=CA * If there is a firewall between you and nameservers you want * to talk to, you might need to uncomment the query-source * directive below. Previous versions of BIND always asked * questions using port 53, but BIND 8.1 uses an unprivileged * port by default. =F5=D3=D4=C1=CE=CF=D7=CC=C5=CE =C4=C5=CA=D3=D4=D7=C9=D4=C5=CC=D8=CE=CF = BIND 8.2 =E4=CF=C2=C1=D7=C9=CC =D3=CC=C5=C4=D5=C0=DD=C9=C5 =D0=D2=C1=D7=C9=CC=C1, = =D2=C5=DA=D5=CC=D8=D4=C1=D4 =D0=D2=C5=D6=CE=C9=CA. ipchains -A output -i $EXTERNAL_INTERFACE -p udp -s $IPADDR $UNPRIVPORTS -d $NAMESERVER_1 53 -j ACCEPT ipchains -A input -i $EXTERNAL_INTERFACE -p udp -s $NAMESERVER_1 53 -d $IPADDR $UNPRIVPORTS -j ACCEPT ipchains -A output -i $EXTERNAL_INTERFACE -p udp -s $IPADDR $UNPRIVPORTS -d $NAMESERVER_2 53 -j ACCEPT ipchains -A input -i $EXTERNAL_INTERFACE -p udp -s $NAMESERVER_2 53 -d $IPADDR $UNPRIVPORTS -j ACCEPT =C7=C4=C5 NAMESERVER_1=3D"195.12.66.1" NAMESERVER_2=3D"195.12.66.65" UNPRIVPORTS=3D"1024:65535" IPADDR=3D"195.12.68.190"