Odd Firewall Problem

Duston, Hal hdusto01 at sprintspectrum.com
Mon May 14 02:07:28 CDT 2001


Steven,

Quick question.  Are the servers you are using for DNS inside or 
outside of the firewall.  If they are outside, make sure that the 
DNS traffic can get through the firewall.  The actual recommended 
approach, however, is to set up a caching DNS server inside the 
firewall, so you don't have to let the rest of the machines push 
DNS traffic through.

HTH,
Hal

Steven L. Brendtro [sbrendtro at home.com] wrote:
> 
> Hello all,
>
> I recently set up a firewall to protect a private network which has been
up
> and running for about a month with no real problems.  I recently made some
> modifications to the network (note to the ipchains rulesets) and have the
> following problem...  Machines on the private network can ping the
Internet,
> having the traffic masqueraded, and they can even access websites by IP
> address, but nothing works with domain names.
>
> I would figure this to be a domain issue, but the firewall uses the same
DNS
> servers as the clients on the private net and the firewall has no problem
> resolving any names.
>
> I appreciate any help you can give... I have lost much hair and sleep over
> this one so far... and the 20+ users on the private net aren't very happy.
>
> Thanks,
> Steven Brendtro
> Lee's Summit, MO




More information about the Kclug mailing list