SuSEfirewall refuses to work after nameservers are definded (was: Bei Nutzung von...)
![](https://seccdn.libravatar.org/avatar/f1e465448e4b02a7492d2fbc5fc050a3.jpg?s=120&d=mm&r=g)
Hi! I have to apologize for the german-only mail I sent a couple of minutes before. A subscriber of this list informed me, that this mailing-list is lead in English. I'm sorry I didn't know this, I found the address in a German SuSE-manual. Nevertheless I seek and hope for your help ;-) The firewall on our freshly installed box runs fine as long as no nameservers are defined. I'm talking about the nameservers of our provider, we don't run named on our machine. After defining two nameservers using Yast, the command dr-gonzo:/etc/rc.config.d # rcSuSEfirewall restart delivers Starting Firewall Initialization: (phase 3 of 3) and stops. If the firewall is started during a reboot it stops after phase2. Without nameservers in /etc/resolve.conf it is possible to restart the firewall: dr-gonzo:/etc/rc.config.d # rcSuSEfirewall restart Starting Firewall Initialization: (phase 3 of 3) Warning: No nameservers in /etc/resolv.conf! done We configured the firewall as desribed in the manual, I have no idea, what might be wrong. Maybe these variables can help you: FW_SERVICES_EXTERNAL_TCP="www smtp domain" FW_SERVICES_EXTERNAL_UDP="domain" FW_SERVICES_EXTERNAL_IP="" FW_ALLOW_INCOMING_HIGHPORTS_TCP="yes" FW_ALLOW_INCOMING_HIGHPORTS_UDP="dns" FW_SERVICE_DNS="no" Do you have the right hint for us? Thanks a lot and kind regards from Cologne, Thorsten
![](https://seccdn.libravatar.org/avatar/45ad223dafbcc98e0ea71ee0b0dcd3c1.jpg?s=120&d=mm&r=g)
FW_SERVICES_EXTERNAL_TCP="www smtp domain" FW_SERVICES_EXTERNAL_UDP="domain" FW_SERVICES_EXTERNAL_IP="" FW_ALLOW_INCOMING_HIGHPORTS_TCP="yes" FW_ALLOW_INCOMING_HIGHPORTS_UDP="dns" FW_SERVICE_DNS="no" I think setting FW_SERVICES_EXTERNAL_TCP to domain is supposed to allow external people to query you name server the UDP rule as well. I guess that is all you need. You could also set query-source port 53; in your named.conf
participants (2)
-
semat
-
Thorsten Büker