Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 16 Oct 1998 01:29:54 +1300 (NZDT)
From:      Andrew McNaughton <andrew@squiz.co.nz>
To:        Dmitry Sergeev <dish77@my-dejanews.com>
Cc:        freebsd-security@FreeBSD.ORG
Subject:   Re: Firewall log and setup
Message-ID:  <Pine.BSF.4.01.9810160125530.355-100000@aniwa.sky>
In-Reply-To: <PBMKMEPGHAKDCAAA@my-dejanews.com>

next in thread | previous in thread | raw e-mail | index | archive | help

On Thu, 15 Oct 1998, Dmitry Sergeev wrote:

> Hi!
> When i have installed FreeBSD 2.2.7 my firewall become to log this packets..(see log below)
> When i worked with FreeBSD 2.2.5 everything was ok. These denied UDP packets
> come from root DNS servers which are listed in named.root

If you don't want your named to try to talk to name services all over the
place you should tell it to only forward requests to a list of IP's you
specify using 

forwarders your_privder_dns some_other_dns
options forward-only


> Maybe someone comment this situation?
> What does Fragment = 34 mean?

I think this is a separate issue.  dns packets are mostly fairly small and
shouldn't need to be fragmented.

Andrew



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.01.9810160125530.355-100000>