Security Basics mailing list archives

RE: Can't Resolve from behind firewall


From: YashPal Singh <ysingh () quark co in>
Date: Sat, 19 Oct 2002 11:00:21 +0530

I think you have not allowed DNS incoming traffic. To debug your problem
allow incoming udp packets from any to your ipaddress. I guess this is the
only problem bcoz DNS reply from ur ISP get blocked by your Firewall.
Moreover to check that this problem is just bcoz of firewall....put allow
all rule at the top and then check if you are able to get DNS replies.

Yash

-----Original Message-----
From: Ahmed.Shazly [mailto:ahmed.shazly () hotpop com]
Sent: Thursday, October 17, 2002 5:45 AM
To: security-basics () securityfocus com
Subject: Can't Resolve from behind firewall


Hi everyone,
  I Just got a PIX 501 for my company and since they have strict policies i
do have to strict usage to port 80, now with the PDM i try permiting
outgoing traffic from the my local net on port 80 to any outside port and
permit outgoing traffic on port 53 for the DNS to any port since we use the
DNS server of our ISP. the only thing that happens is that i still can't
resolve websites and they only work if i use their IP addresses. i do use
PAT and i'm not sure wheather it has anything to do with whats going on any
suggestions?

Regards,
     A.Shazly



Current thread: