Re: Firewall rules and features

2015-11-10 Thread Stuart Henderson
On 2015-11-10, sven falempin wrote: > Ok , I agree, and thank you for the accurate answer. > > > OTOH the server was rejecting all the other request, (i do not think it > was badly configure) > and it ended up rejecting the good one also (after a lng time of use) > I first look in nsd manpage

Re: Firewall rules and features

2015-11-09 Thread sven falempin
Ok , I agree, and thank you for the accurate answer. OTOH the server was rejecting all the other request, (i do not think it was badly configure) and it ended up rejecting the good one also (after a lng time of use) I first look in nsd manpages to see if i could figure why and found nothing

Re: Firewall rules and features

2015-11-09 Thread Nick Holland
On 11/09/15 16:45, sven falempin wrote: > For the first time ever i did something with iptable > that i dont know how to do (simply) with > pf. > Something i think it is usefull. > > I have a domain server, nsd, it serves whatever.com, Authoritative server, then. > the server is like flooded wit

Re: Firewall rules and features

2015-11-09 Thread sven falempin
Thank you Pedro fot http://ftp.openbsd.org/pub/OpenBSD/5.8/packages/amd64/dnsfilter-0.4p0.tgz I am not sure this is as good as it could be, according to the mail there is room for improvement. Worth a test , and it s better to improve than to add up yet another small program, i wonder how good i

Re: Firewall rules and features

2015-11-09 Thread Pedro Caetano
Hi, I guess one could use pf's divert-to and dnsfilter. http://marc.info/?l=openbsd-misc&m=134187877220567&w=2 Regards, Pedro Caetano On Mon, Nov 9, 2015 at 9:45 PM, sven falempin wrote: > For the first time ever i did something with iptable > that i dont know how to do (simply) with > pf. >