Bug 25408 - Default firewall configuration blocks name resolution
Default firewall configuration blocks name resolution
Status: CLOSED DUPLICATE of bug 25951
Product: Red Hat Linux
Classification: Retired
Component: anaconda (Show other bugs)
i386 Linux
medium Severity medium
: ---
: ---
Assigned To: Bill Nottingham
Brock Organ
Depends On:
  Show dependency treegraph
Reported: 2001-01-31 16:18 EST by Dan Taylor
Modified: 2014-03-16 22:18 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2001-02-01 13:39:09 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Dan Taylor 2001-01-31 16:18:40 EST
During installation the default firewall option (high) produces ipchains 
rules that prevent the local machine from doing proper name resolution.
The /etc/sysconfig/ipchains file looks like this:

:input ACCEPT
:forward ACCEPT
:output ACCEPT
-A input -s 0/0 -d 0/0 -i lo -j ACCEPT
-A input -s 0/0 -d 0/0 -p tcp -y -j DENY
-A input -s 0/0 -d 0/0 -p udp -j DENY

The last line is blocking the return packets from the name server.   
Modifying the last line to this resolves the issue:

-A input -s 0/0 ! 53 -d 0/0 -p udp -j DENY
Comment 1 Bill Nottingham 2001-02-01 11:43:57 EST
Did you not set up a nameserver during the install?
Comment 2 Daniel Roesen 2001-02-01 13:05:20 EST
Fixing version to "beta3"
Comment 3 Dan Taylor 2001-02-01 13:10:00 EST
Yes a nameserver was already setup. here is my /etc/resolv.conf  

search localdomain

The ipchains rule prevents the client from being able to resolve any names 
Comment 4 Bill Nottingham 2001-02-01 13:23:17 EST
Where did you configure the networking setup?
Comment 5 Dan Taylor 2001-02-01 13:26:09 EST
It was setup during the install to use dhcp.
Comment 6 Bill Nottingham 2001-02-01 13:32:29 EST
Was this a local install or a network install?
Comment 7 Dan Taylor 2001-02-01 13:39:05 EST
Comment 8 Bill Nottingham 2001-02-05 11:00:28 EST

*** This bug has been marked as a duplicate of 25951 ***

Note You need to log in before you can comment on or make changes to this bug.