{"id":1826,"date":"2011-03-24T10:22:55","date_gmt":"2011-03-24T10:22:55","guid":{"rendered":"http:\/\/wiki.freeiz.com\/?p=1826"},"modified":"2016-08-09T12:06:44","modified_gmt":"2016-08-09T12:06:44","slug":"linux-iptables-dns-chain","status":"publish","type":"post","link":"https:\/\/wiki-see.info\/wp\/2011\/03\/24\/linux-iptables-dns-chain\/","title":{"rendered":"Linux Iptables DNS Chain"},"content":{"rendered":"<p><span style=\"color: #000000;\"><span style=\"color: #800000;\">Allow internet access to<\/span> <span style=\"color: #000080;\">DNS Server public address<\/span>. <span style=\"color: #800000;\">Lets go ahead and create the rules needed<\/span>.<\/span><\/p>\n<p><span style=\"color: #800000;\">Lets Create the nat dns Chain<\/span> :<\/p>\n<p><span style=\"color: #000000;\">sudo iptables -N<\/span> <span style=\"color: #000080;\">dns<\/span><br \/>\n!<br \/>\n<span style=\"color: #800000;\">Allow local access to <span style=\"color: #000080;\">NaT traffic <\/span>out to internet <span style=\"color: #000080;\">DNS Servers<\/span><\/span><span style=\"color: #000080;\">.<\/span><br \/>\nA<span style=\"color: #800000;\">llow <span style=\"color: #000080;\">POSTROUTING Chain<\/span>, DNS Traffic to jump to Chain <span style=\"color: #000080;\">dns<\/span><\/span><br \/>\n!<br \/>\n<span style=\"color: #000000;\">sudo iptables -I<\/span> P<span style=\"color: #000080;\">OSTROUTING<\/span> <span style=\"color: #000000;\">19 -i eth0 -s 10.10.0.0\/16 -p udp -m udp &#8211;dport 53 &#8211;<\/span>j <span style=\"color: #000080;\">dns<\/span><br \/>\n!<\/p>\n<p><span style=\"color: #800000;\">Allow local access to Public DNS Server to ACCEPT <\/span>:<br \/>\n<span style=\"color: #000000;\">sudo iptables &#8211;<\/span><span style=\"color: #000000;\">I<\/span> <span style=\"color: #000080;\">dns<\/span><span style=\"color: #000000;\"> -i eth1 -d 80.84.86.80 -p udp -m udp &#8211;dport 53 &#8211;<\/span><span style=\"color: #000000;\">j<\/span> <span style=\"color: #000080;\">ACCEPT<\/span><br \/>\n<span style=\"color: #000000;\">sudo iptables -I<\/span> <span style=\"color: #000080;\">dns<\/span><span style=\"color: #000000;\"> -i eth1 -d 80.84.86.81 -p udp -m udp &#8211;dport 53 -j<\/span> <span style=\"color: #000080;\">ACCEPT<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Allow internet access to DNS Server public address. Lets go ahead and create the rules needed. Lets Create the nat dns Chain : sudo iptables -N dns ! Allow local access to NaT traffic out to internet DNS Servers. Allow POSTROUTING Chain, DNS Traffic to jump to Chain dns ! sudo iptables -I POSTROUTING 19 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[],"class_list":["post-1826","post","type-post","status-publish","format-standard","hentry","category-iptables-linux"],"_links":{"self":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/1826","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/comments?post=1826"}],"version-history":[{"count":1,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/1826\/revisions"}],"predecessor-version":[{"id":4913,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/1826\/revisions\/4913"}],"wp:attachment":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/media?parent=1826"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/categories?post=1826"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/tags?post=1826"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}