Discussion:
[Shorewall-users] Strange problem
John Knight Jr
2017-02-14 06:26:50 UTC
Permalink
I've been using shorewall for years but I can't seem to figure this one out.

When I try to access 'www.walgreens.com' the DNS resolver times out with
shorewall running.

I've narrowed it down to their asset storage on www.wag-static.com.

Using the following command:

dig +trace www.wag-static.com

When shorewall is stopped, the query succeeds.

If shorewall is active, the query times out trying to access walgreen's
name servers.

I've attached a shorewall dump.

Thousands of other queries work fine, this one gets stuck somewhere.

Thanks for any assistance.
John
Tom Eastep
2017-02-15 22:47:54 UTC
Permalink
Post by John Knight Jr
I've been using shorewall for years but I can't seem to figure this one out.
When I try to access 'www.walgreens.com' the DNS resolver times out
with shorewall running.
I've narrowed it down to their asset storage on
www.wag-static.com.
dig +trace www.wag-static.com
When shorewall is stopped, the query succeeds.
If shorewall is active, the query times out trying to access
walgreen's name servers.
I've attached a shorewall dump.
Thousands of other queries work fine, this one gets stuck
somewhere.
Is their authoritative name server listed in your Blacklistnets ipset?

- -Tom
- --
Tom Eastep \ When I die, I want to go like my Grandfather who
Shoreline, \ died peacefully in his sleep. Not screaming like
Washington, USA \ all of the passengers in his car
http://shorewall.net \________________________________________________
Loading...