basic iptables question

This is a discussion on basic iptables question within the Linux Security forums, part of the System Security and Security Related category; When defining a network address why does the iptables man pages say its a bad idea to use a domain ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 03-22-2005
Aussie Fred
 
Posts: n/a
Default basic iptables question

When defining a network address why does the iptables man pages say its a
bad idea to use a domain name instead of an IP address?

Reply With Quote
  #2 (permalink)  
Old 03-22-2005
Chris Lowth
 
Posts: n/a
Default Re: basic iptables question

Aussie Fred wrote:
> When defining a network address why does the iptables man pages say its a
> bad idea to use a domain name instead of an IP address?
>


One possible reason is that some domain names resolve to multiple
addresses. In such cases, iptables needs to know which of the IPs
provided to use, or whether to use all of them in some way.

--
Scriptable IpTables rules with "Rope"
http://www.lowth.com/rope
Reply With Quote
  #3 (permalink)  
Old 03-22-2005
Keith Keller
 
Posts: n/a
Default Re: basic iptables question

On 2005-03-21, Aussie Fred <fred012@hotmail.com> wrote:
> When defining a network address why does the iptables man pages say its a
> bad idea to use a domain name instead of an IP address?


Two possible reasons:

1) DNS may not be available at the time the iptables command
executes (often you want iptables to run before the interfaces
are up)

2) If you don't control the DNS of the name you are specifying,
the owner of the domain can spoof any IP he wants to get around
your rules

--keith

--
kkeller-usenet@wombat.san-francisco.ca.us
(try just my userid to email me)
AOLSFAQ=http://wombat.san-francisco.ca.us/cgi-bin/fom
see X- headers for PGP signature information

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 04:13 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0