Saturday, March 21, 2009

ateşduvarında opendns ile filtre

duvar:~# cat /etc/bind/named.conf.options
options {
directory "/var/cache/bind";

// If there is a firewall between you and nameservers you want
// to talk to, you may need to fix the firewall to allow multiple
// ports to talk. See http://www.kb.cert.org/vuls/id/800113

// If your ISP provided one or more IP addresses for stable
// nameservers, you probably want to use them as forwarders.
// Uncomment the following block, and insert the addresses replacing
// the all-0's placeholder.

// forwarders {
// 0.0.0.0;
// };
forwarders { 208.67.222.222; 208.67.220.220; };
auth-nxdomain no; # conform to RFC1035
listen-on-v6 { any; };
};

iptables kuralları

-A FORWARD -d 208.67.222.222/32 -p udp -m udp --dport 53 -m state --state NEW -j ACCEPT
-A FORWARD -d 208.67.220.220/32 -p udp -m udp --dport 53 -m state --state NEW -j ACCEPT

No comments: