Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.networking > #374
| From | "S.K.R. de Jong" <SKRdJ@nowhere.net> |
|---|---|
| Newsgroups | comp.os.linux.networking |
| Subject | Re: Dropping incoming connections from a given domain |
| Date | 2011-06-17 00:12 +0000 |
| Organization | albasani.net |
| Message-ID | <ite65q$2la$1@news.albasani.net> (permalink) |
| References | <itdltg$6dr$1@news.albasani.net> <itdos3$2ufn$1@saria.nerim.net> |
On Thu, 16 Jun 2011 22:25:38 +0200, Pascal Hambourg wrote: > Hello, > > S.K.R. de Jong a écrit : >> I am looking for an iptables incantation that would allow all >> connection attempts from IP addresses in a given domain. Is this >> possible? > > What do you mean by "IP addresses in a given domain" ? > > If you mean the reverse DNS being in a given domain, not easily. > Iptables rules are run by the kernel and the kernel knows nothing about > DNS. You would need to QUEUE packets and do the reverse DNS resolution > in userland. In that case, can it be done on the basis of matching IP addresses? For instance, would it be possible to get iptables to discard packets from, say, 192.168.xxx.yyy, where xxx and yyy are integers between 0 and 255?
Back to comp.os.linux.networking | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Dropping incoming connections from a given domain "S.K.R. de Jong" <SKRdJ@nowhere.net> - 2011-06-16 19:35 +0000
Re: Dropping incoming connections from a given domain Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-06-16 22:25 +0200
Re: Dropping incoming connections from a given domain Rick Jones <rick.jones2@hp.com> - 2011-06-16 20:29 +0000
Re: Dropping incoming connections from a given domain "S.K.R. de Jong" <SKRdJ@nowhere.net> - 2011-06-17 00:12 +0000
Re: Dropping incoming connections from a given domain Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-06-17 09:08 +0200
csiph-web