RE: 7.3 upgrade: Bind fails when ipchains enabled.

2002-10-04 Thread Langa Kentane
your rulebase to drop and log everything. Go tru the log and see why nothing is coming back to you. Regards LK -Original Message- From: john-paul delaney [mailto:[EMAIL PROTECTED]] Sent: 29 September 2002 16:54 To: [EMAIL PROTECTED] Subject: Re: 7.3 upgrade: Bind fails when ipchains en

Re: 7.3 upgrade: Bind fails when ipchains enabled.

2002-09-29 Thread john-paul delaney
I'm still having difficulty with nslookup from another machine and domain transfer even though I've opened up ports UDP 53 and TCP 53. If I turn off ipchains completely, then all works ok. Anybody know what other ports / protocols should I be looking at? I'm new to ipchains. I've just enabl

Re: 7.3 upgrade: Bind fails when ipchains enabled.

2002-09-26 Thread Mike Burger
The outgoing port is always going to be something higher...the destination port is 53. On Fri, 27 Sep 2002, john-paul delaney wrote: > Thanks Mike... I've turned on 53/tcp (as well as 53/udp) as you suggest and will >force a reload to test. I still have a problem with lookups from the interne

Re: 7.3 upgrade: Bind fails when ipchains enabled.

2002-09-26 Thread john-paul delaney
Thanks Mike... I've turned on 53/tcp (as well as 53/udp) as you suggest and will force a reload to test. I still have a problem with lookups from the internet, as in the following tcpdump extract: - > justatest.com.domain: 12+ A? linuxdoc.org. (30) 05:53:27.724911 justatest.com > ppp-233-153.

Re: 7.3 upgrade: Bind fails when ipchains enabled.

2002-09-26 Thread Mike Burger
For zone transfers, you need to open up port 53/tcp in your firewall. 53/udp is strictly for lookups. On Thu, 26 Sep 2002, john-paul delaney wrote: > > Hello List... > > After upgrading from rh7.0 to 7.3, I've found that Bind doesn't work for zone >updates (I'm using a hidden primary namese

7.3 upgrade: Bind fails when ipchains enabled.

2002-09-26 Thread john-paul delaney
Hello List... After upgrading from rh7.0 to 7.3, I've found that Bind doesn't work for zone updates (I'm using a hidden primary nameserver which refreshes secondary.com nameservers) nor the dig command from the internet even though I had allowed incoming traffic to port 53 (I'm new to ipchain