How about: “lsof -i -n  -P”

From: "Jack Craig" 
<jack.craig.ap...@gmail.com<mailto:jack.craig.ap...@gmail.com>>
Date: Saturday, 14 November 2020 at 21:11:39
To: "Community support for Fedora users" 
<users@lists.fedoraproject.org<mailto:users@lists.fedoraproject.org>>
Subject: Re: F32 bind9 split dns debug

is there an easier way to verify a port access to internal host besides 
wireshark & tcpdump?

On Sat, Nov 14, 2020 at 11:51 AM Jack Craig 
<jack.craig.ap...@gmail.com<mailto:jack.craig.ap...@gmail.com>> wrote:


On Sat, Nov 14, 2020 at 11:33 AM Jack Craig 
<jack.craig.ap...@gmail.com<mailto:jack.craig.ap...@gmail.com>> wrote:

this part looked ok to me, but i am not sure.

now seeing higher throughput, but still got...

14-Nov-2020 11:28:20.993 query-errors: info: client @0x7fc8601c9760 
52.183.97.231#63450 (linuxlighthouse.com<http://linuxlighthouse.com>): view 
external-wan-view: query failed (REFUSED) for 
linuxlighthouse.com/IN/A<http://linuxlighthouse.com/IN/A> at 
../../../bin/named/query.c:7270
14-Nov-2020 11:28:21.030 query-errors: info: client @0x7fc8601c9760 
20.190.57.96#61806 (www.linuxlighthouse.com<http://www.linuxlighthouse.com>): 
view external-wan-view: query failed (REFUSED) for 
www.linuxlighthouse.com/IN/A<http://www.linuxlighthouse.com/IN/A> at 
../../../bin/named/query.c:7270
14-Nov-2020 11:28:21.047 query-errors: info: client @0x7fc8601c9760 
51.143.102.160#49893 (www.linuxlighthouse.com<http://www.linuxlighthouse.com>): 
view external-wan-view: query failed (REFUSED) for 
www.linuxlighthouse.com/IN/NS<http://www.linuxlighthouse.com/IN/NS> at 
../../../bin/named/query.c:7270

how can i see/test a query's processing between default.log & security.log ?
i can see the query, if i could see why it's failing, i'd query this list less. 
;)

www.linuxlighthouse.com/IN/NS<http://www.linuxlighthouse.com/IN/NS> at 
../../../bin/named/query.c:7270

i looked at the query.c @7270 but was unable to gleen any useful insight.

WRT networking, my block of static ip's is from att.com<http://att.com>

i have cascaded routers from att's pace unit to a netgear night hawk that does
port fwding for 53, 80 443 to the 10.0.0.101 sever.
i use the firewall on the att rtr limiting to the above ports to pass through.

the NH logs show connects to 53,80, & 443

i also cranked debug to 10 in named logging, but so far,...

lastly, as F32 comes w/iptables, i migrated to nftables.




Dit bericht kan informatie bevatten die niet voor u is bestemd. Indien u niet 
de geadresseerde bent of dit bericht abusievelijk aan u is toegezonden, wordt u 
verzocht dat aan de afzender te melden en het bericht te verwijderen. De Staat 
aanvaardt geen aansprakelijkheid voor schade, van welke aard ook, die verband 
houdt met risico's verbonden aan het elektronisch verzenden van berichten.

This message may contain information that is not intended for you. If you are 
not the addressee or if this message was sent to you by mistake, you are 
requested to inform the sender and delete the message. The State accepts no 
liability for damage of any kind resulting from the risks inherent in the 
electronic transmission of messages.
_______________________________________________
users mailing list -- users@lists.fedoraproject.org
To unsubscribe send an email to users-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/users@lists.fedoraproject.org

Reply via email to