From owner-freebsd-questions@FreeBSD.ORG Fri Jul 30 18:20:37 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3F26516A4CE for ; Fri, 30 Jul 2004 18:20:37 +0000 (GMT) Received: from mta9.adelphia.net (mta9.adelphia.net [68.168.78.199]) by mx1.FreeBSD.org (Postfix) with ESMTP id DEC5D43D2D for ; Fri, 30 Jul 2004 18:20:36 +0000 (GMT) (envelope-from Barbish3@adelphia.net) Received: from barbish ([67.20.101.71]) by mta9.adelphia.net (InterMail vM.6.01.03.02 201-2131-111-104-20040324) with SMTP id <20040730181937.TTVD2023.mta9.adelphia.net@barbish>; Fri, 30 Jul 2004 14:19:37 -0400 From: "JJB" To: "James A. Coulter" , Date: Fri, 30 Jul 2004 14:19:36 -0400 Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: 7bit X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook IMO, Build 9.0.6604 (9.0.2911.0) X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1409 In-Reply-To: <002801c47645$51cfcb50$6e01a8c0@sabrina> Importance: Normal Subject: RE: Firewall Rule Set not allowing access to DNS servers? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: Barbish3@adelphia.net List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 30 Jul 2004 18:20:37 -0000 Change this ipfw rule from 00005 allow ip from any to any via xl0 To 00005 allow ip from any to any via dc0 because dc0 is the lan interface name and not xl0. Change these statement in rc.conf because you have interface name backwards. Dc1 is the NIC connected to your cable modem and you want to get DHCP info from your ISP. Dc0 is the NIC connected to your LAN. From ifconfig_dc1="DHCP" ifconfig_dc0="inet 192.168.1.1 netmask 255.255.255.0" to ifconfig_dc0="DHCP" ifconfig_dc1="inet 192.168.1.1 netmask 255.255.255.0" You do not say how your LAN PCs get their ip address. You can hard code them on each LAN PC or you have to run isc-dhcp-server on your Gateway box to auto assign ip address to LAN PCs. -----Original Message----- From: owner-freebsd-questions@freebsd.org [mailto:owner-freebsd-questions@freebsd.org]On Behalf Of James A. Coulter Sent: Friday, July 30, 2004 10:56 AM To: freebsd-questions@freebsd.org Subject: Firewall Rule Set not allowing access to DNS servers? I am using FreeBSD 4.10 as a gateway/router for a small home LAN. My outside interface (dc1) is connected to a cable modem and is configured for DHCP. I have compiled and installed a custome kernel with IPFIREWALL and IPDIVERT options and with a rule set allowing any to any with no problems I am in the process of adding a proper rule set to provide security. I was referred to http://freebsd.a1poweruser.com:6088/FBSD_firewall/ and installed the Stateful + NATD Rule Set modified for my outside interface, domain name servers, and DHCP server. I can ping IP addresses and pass SMTP mail back and forth from the gateway/router and all machines on the LAN, but I cannot ping URLs - I am getting "ping: cannot resolve www.freebsd.org: Host name lookup failure" errors. This is what ipfw -a list looks like: sara# ipfw -a list 00005 0 0 allow ip from any to any via xl0 00010 52 3640 allow ip from any to any via lo0 00014 0 0 divert 8668 ip from any to any in recv dc1 00015 0 0 check-state 00020 0 0 skipto 800 tcp from any to 68.105.161.20 53 keep-state out xmit dc1 setup 00021 0 0 skipto 800 tcp from any to 68.1.18.25 53 keep-state out xmit dc1 setup 00022 0 0 skipto 800 tcp from any to 68.10.16.30 53 keep-state out xmit dc1 setup 00030 0 0 skipto 800 udp from any to 172.19.17.22 67 keep-state out xmit dc1 00040 0 0 skipto 800 tcp from any to any 80 keep-state out xmit dc1 setup 00050 0 0 skipto 800 tcp from any to any 443 keep-state out xmit dc1 setup 00060 0 0 skipto 800 tcp from any to any 25 keep-state out xmit dc1 setup 00061 0 0 skipto 800 tcp from any to any 110 keep-state out xmit dc1 setup 00070 0 0 skipto 800 tcp from me to any uid root keep-state out xmit dc1 setup 00080 0 0 skipto 800 icmp from any to any keep-state out xmit dc1 00090 0 0 skipto 800 tcp from any to any 37 keep-state out xmit dc1 setup 00100 0 0 skipto 800 tcp from any to any 119 keep-state out xmit dc1 setup 00110 0 0 skipto 800 tcp from any to any 22 keep-state out xmit dc1 setup 00120 0 0 skipto 800 tcp from any to any 43 keep-state out xmit dc1 setup 00130 0 0 skipto 800 udp from any to any 123 keep-state out xmit dc1 00300 0 0 deny ip from 192.168.0.0/16 to any in recv dc1 00301 0 0 deny ip from 172.16.0.0/12 to any in recv dc1 00302 0 0 deny ip from 10.0.0.0/8 to any in recv dc1 00303 0 0 deny ip from 127.0.0.0/8 to any in recv dc1 00304 0 0 deny ip from 0.0.0.0/8 to any in recv dc1 00305 0 0 deny ip from 169.254.0.0/16 to any in recv dc1 00306 0 0 deny ip from 192.0.2.0/24 to any in recv dc1 00307 0 0 deny ip from 204.152.64.0/23 to any in recv dc1 00308 0 0 deny ip from 224.0.0.0/3 to any in recv dc1 00315 0 0 deny tcp from any to any 113 in recv dc1 00320 0 0 deny tcp from any to any 137 in recv dc1 00321 0 0 deny tcp from any to any 138 in recv dc1 00322 0 0 deny tcp from any to any 139 in recv dc1 00323 0 0 deny tcp from any to any 81 in recv dc1 00330 0 0 deny ip from any to any in recv dc1 frag 00332 0 0 deny tcp from any to any in recv dc1 established 00360 0 0 allow udp from 172.19.17.22 to any 68 keep-state in recv dc1 00370 0 0 allow tcp from any to me 80 limit src-addr 2 in recv dc1 setup 00370 0 0 allow tcp from any to me 8888 limit src-addr 2 in recv dc1 setup 00380 0 0 allow tcp from any to me 22 limit src-addr 2 in recv dc1 setup 00400 0 0 deny log logamount 10 ip from any to any in recv dc1 00450 81 5288 deny log logamount 10 ip from any to any out xmit dc1 00800 0 0 divert 8668 ip from any to any out xmit dc1 00801 645 59255 allow ip from any to any 00999 0 0 deny log logamount 10 ip from any to any 65535 1 347 deny ip from any to any This is what my /etc/rc.conf looks like: hostname="sara.mshome.net" ifconfig_dc1="DHCP" ifconfig_dc0="inet 192.168.1.1 netmask 255.255.255.0" firewall_enable="YES" firewall_script="/etc/ipfw.rules" firewall_logging="YES" kern_securelevel_enable="NO" linux_enable="YES" moused_enable="YES" named_enable="YES" nfs_client_enable="YES" nfs_reserved_port_only="YES" nfs_server_enable="YES" sendmail_enable="YES" sshd_enable="YES" usbd_enable="YES" ntpd_enable="YES" inetd_enable="YES" gateway_enable="YES" natd_enable="YES" natd_interface="dc1" natd_flags="-dynamic" Finally, this is what /etc/resolv.conf looks like: sara# more /etc/resolv.conf search pn.at.cox.net nameserver 68.105.161.20 nameserver 68.1.18.25 nameserver 68.10.16.30 Any ideas? Thanks, Jim C. _______________________________________________ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"