Re: iptables -d fqdn instead of IP

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On 10/29/2009 10:29 AM, Vinicius Coque wrote:
>> does it work to define iptables rules with a fqdn as destination
>> instead of an IP address? Or is it useful to resolve the name first
>> using e.g. nslookup, writing the result to a variable which is then
>> used within the -d statement?

I guess that depends on what you are trying to achieve, afaik iptables 
will not hit DNS for each packet, and will only resolve at time of table 
/ policy creation.

- KB
_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
http://lists.centos.org/mailman/listinfo/centos

[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux