mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Richard Hartmann" <richih.mailinglist@gmail.com>
To: "Ray Lee" <ray-lk@madrabbit.org>
Cc: "Willy Tarreau" <w@1wt.eu>, linux-kernel@vger.kernel.org
Subject: Re: iptables, NAT, DNS & Dan Kaminsky
Date: Fri, 1 Aug 2008 14:30:24 +0200	[thread overview]
Message-ID: <2d460de70808010530j717dc5bdm73a44178605089e1@mail.gmail.com> (raw)
In-Reply-To: <2c0942db0807311436p6c61d2f0o9bfe67ffeaaf0e91@mail.gmail.com>

We are drifting from the initial topic, but oh well.. :)

On Thu, Jul 31, 2008 at 23:36, Ray Lee <ray-lk@madrabbit.org> wrote:


> or placing the DNS resolver behind a NAT
> masquerading firewall that does strict response dropping if a response
> comes from the wrong host. (There used to be an option in the kernel
> to deal with that -- loose source routing or somesuch, but I think
> that's a by-gone from the 2.4 era.)

You do not need a NAT to do this, you simply need to block packets
with a source address that does not match the routes your router has
in his routing table. Other than ISP end-costumers and a few other
very clearly defined situations, this is highly non-trivial, though. Some
people still do this, but in most cases, it has proved impractical and
a source of many 'strange' errors.


> So, to answer Richard, yes something like that should work. I'm not an
> iptables guru by any means, but what you should do is set up a machine
> with that, and sniff the output of the DNS server before and after
> enabling that line to verify that it works.

I know that this is possible.
What I wanted to know is what kernel versions do what [automagically]
and in what way.


> The better solution, of course, is to update your DNS server to allow
> it to do the source port randomization itself.

Of course. But I want to fully understand all cases and this is the last
area I still lack information on.


Thanks,
Richard

      reply	other threads:[~2008-08-01 12:45 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-07-30 14:53 Richard Hartmann
2008-07-30 19:55 ` Willy Tarreau
2008-07-31 14:59   ` Richard Hartmann
2008-07-31 21:14     ` Willy Tarreau
2008-07-31 21:36       ` Ray Lee
2008-08-01 12:30         ` Richard Hartmann [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2d460de70808010530j717dc5bdm73a44178605089e1@mail.gmail.com \
    --to=richih.mailinglist@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=ray-lk@madrabbit.org \
    --cc=w@1wt.eu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®