Ray,

This appears to have been a DNS setup problem on my
part.  After working through your e-mail, I went back
and reread "Chapter 3.  Using dnsmasq" of the
Bering-uClib User's guide.  I had not followed the
directions in "3.5 Using dnsmasq with ppp/pppoe".

The Shorewall "Basic Two-Interface Firewall" guide has
not been updated for Bering users using dnsmasq.lrp:

http://www.shorewall.net/two-interface.htm#id2502019 

"You can configure a Caching Name Server on your
firewall. Red Hat� has an RPM for a caching name
server (the RPM also requires the bindRPM) and for
Bering users, there is dnscache.lrp. If you take this
approach, you configure your internal systems to use
the firewall itself as their primary (and only) name
server. You use the internal IP address of the
firewall (10.10.10.254 in the example above) for the
name server address. To allow your local systems to
talk to your caching name server, you must open port
53 (both UDP and TCP) from the local network to the
firewall; you do that by adding the following rules in
/etc/shorewall/rules."

#ACTION    SOURCE    DEST               PROTO     DEST
PORT(S)
AllowDNS   loc       fw

Based on this, I turned off "Obtain DNS server address
automatically" on my Windows XP workstation in network
TCP/IP properties and set the system to use the
internal IP address of the firewall as the primary and
only named server (192.168.1.254).  This seeems to
work and I am able to "surf the web", although I do
not know if this is the best way to set up the DNS
server address.  I also tried "Obtain DNS server
address automatically" and this appeared to work as
well.  Suggestions would be appreciated.

[Note: In Bering-uClib 2.2, /etc/shorewall/rules
appears to have a line that opens port 53 for UDP but
not for TCP, as recommended above for dnscache.lrp.]

I ran ipconfig /all:

Windows IP Configuration

        Host Name . . . . . . . . . . . . : parent
        Primary Dns Suffix  . . . . . . . :
        Node Type . . . . . . . . . . . . : Unknown
        IP Routing Enabled. . . . . . . . : No
        WINS Proxy Enabled. . . . . . . . : No
        DNS Suffix Search List. . . . . . :
private.network

Ethernet adapter Local Area Connection 3:

        Connection-specific DNS Suffix  . :
private.network
        Description . . . . . . . . . . . : NVIDIA
nForce MCP Networking Adapter

        Physical Address. . . . . . . . . :
00-0E-A6-6F-9F-7C
        Dhcp Enabled. . . . . . . . . . . : Yes
        Autoconfiguration Enabled . . . . : Yes
        IP Address. . . . . . . . . . . . :
192.168.1.1
        Subnet Mask . . . . . . . . . . . :
255.255.255.0
        Default Gateway . . . . . . . . . :
192.168.1.254
        DHCP Server . . . . . . . . . . . :
192.168.1.254
        DNS Servers . . . . . . . . . . . :
192.168.1.254
        Lease Obtained. . . . . . . . . . : Saturday,
September 18, 2004 11:07:3
0 PM
        Lease Expires . . . . . . . . . . : Sunday,
September 19, 2004 11:07:30 AM

I will let the system run overnight and see what
happens.

Thanks.

Matt


-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
------------------------------------------------------------------------
leaf-user mailing list: [EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user
SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html

Reply via email to