/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Raul Carvalho wrote:

>  I have a system whose connection to the Internet is a dial-on-demand
> solution based on a 56K V90 modem to my ISP.
> 
>  Since the connection is paid, I choosed to have a DNS server for my local
> LAN, but to avoid boot DNS queries, thus bringing the line up all the
> time, I have removed the "." entry in named.conf (to ignore root.cache
> file).
> 
>  If my local DNS cannot resolv hostnames (ex: external names), a second
> entry in /etc/resolv.conf solves this problem.
> 
>  All this helps understanding my question:
> 
>  Can I filter with ipchains packets comming to outside my LAN by hostname,
> avoiding DNS queries? Example: If I want to prevent users from connecting
> to, say, playboy.com domain, since I don't know the network adresses or
> masks, will ipchains bring up a DNS query or can it filter the packets
> just by its hostname?
> 
>  It doesn't seem logic bringing up the line to in the end filter the
> packets..
> 
>  Thanks for any help,
>  Raul

ipchains can't do this but if you go to
http://www.zip.com.au/~raf2/lib/software/firewall
and download the latest version, you'll find a
utility called dns2ip which reads stdin, replacing
all domain names with their corresponding ip address(es).

this will let you write your firewall scripts using domain
names, filter them through dns2ip, and then execute the result.
you'll have to rerun dns2ip over the script regularly to catch
ip address changes.

raf

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to