Re: [Dnsmasq-discuss] DNSMasq and DNS reflection attacks

2013-10-25 Thread René van Dorst
I am testing my current setup with dnsmasq as an authorized server and a 3 slave dns server. I am using a standard domain register with slave dns support. ( www.nxs.nl ) Only the slave dns servers has access from the internet to dnsmasq, the rest is blocked by the firewall. This setup adds a

[Dnsmasq-discuss] BUG in synth-domain.

2013-10-25 Thread René van Dorst
Only tested with ipv4 with the latest git version. Dnsmasq doesn't accept: synth-domain=domain,ip address,ip address,prefix It does accept: synth-domain=domain,ip address,ip address or synth-domain=domain, ip address/netmask,prefix Greats, René van

Re: [Dnsmasq-discuss] DNSMasq and DNS reflection attacks

2013-10-25 Thread Simon Kelley
On 24/10/13 18:11, Brian Rak wrote: Ah, but that's the problem. The machines I'm referring to only have one interface. So, I'm primarily running this on virtual machine hosts. They have one connection to the internet, and no internal network. So, for example we have a virtual machine host

Re: [Dnsmasq-discuss] DNSMasq and DNS reflection attacks

2013-10-25 Thread Simon Kelley
On 24/10/13 21:40, richardvo...@gmail.com wrote: Sorry, I should mention only drop packets in state NEW, you don't want to drop replies to your own queries. Dropping replies to your own queries shouldn't be a problem. The queries originate from ports other than 53 (normally, a newly

Re: [Dnsmasq-discuss] DNSMasq and DNS reflection attacks

2013-10-25 Thread Simon Kelley
On 24/10/13 23:03, /dev/rob0 wrote: On Thu, Oct 24, 2013 at 05:28:29PM +0100, Simon Kelley wrote: On 24/10/13 17:03, Brian Rak wrote: We've recently undertaken a project to clean up our network, and lock down all the open DNS resolvers. As you may know, these are very frequently used for DDOS

Re: [Dnsmasq-discuss] DNSMasq and DNS reflection attacks

2013-10-25 Thread Simon Kelley
On 24/10/13 23:41, Vladislav Grishenko wrote: From: Simon Kelley Sent: Thursday, October 24, 2013 11:00 PM So, don't use --bind-interfaces. If you're on Linux, you can use --bind- dynamic instead if you're running multiple dnsmasq instances. So, on linux --bind-interfaces can be just an

[Dnsmasq-discuss] Announce: dnsmasq-2.67

2013-10-25 Thread Simon Kelley
dnsmsaq-2.67 is now available to download from http://www.thekelleys.org.uk/dnsmasq/dnsmasq-2.67.tar.gz Cheers, Simon. ___ Dnsmasq-discuss mailing list Dnsmasq-discuss@lists.thekelleys.org.uk

[Dnsmasq-discuss] What is the required configuration for enabling periodic RA's

2013-10-25 Thread Gordon Scott
Hi there, I'm trying to use dnsmasq to provide RA for stateless IPV6 configuration. Does anyone know the configuration required to get dnsmasq to send out RA's periodically? So far I seem to only see RA's be sent after a DHCP request occurs. I'm trying to set this up on a router that has a

Re: [Dnsmasq-discuss] What is the required configuration for enabling periodic RA's

2013-10-25 Thread Simon Kelley
On 25/10/13 16:28, Gordon Scott wrote: Hi there, I'm trying to use dnsmasq to provide RA for stateless IPV6 configuration. Does anyone know the configuration required to get dnsmasq to send out RA's periodically? So far I seem to only see RA's be sent after a DHCP request occurs. How are you

Re: [Dnsmasq-discuss] DNSMasq and DNS reflection attacks

2013-10-25 Thread Vladislav Grishenko
From: Simon Kelley Sent: Friday, October 25, 2013 4:15 PM On 24/10/13 23:41, Vladislav Grishenko wrote: From: Simon Kelley Sent: Thursday, October 24, 2013 11:00 PM So, don't use --bind-interfaces. If you're on Linux, you can use --bind- dynamic instead if you're running multiple