(43p-aix) [dalan] nslookup 43p
*** Can't find server name for address refused
*** Default servers are not available
(43p-aix) [dalan]
I have shut off the firewall and SE-Linux on the Fedora system. I'm not sure
why the fedora system is blocking/refusing the request coming from another
I even put the following entries in iptables.
iptables -A INPUT -p udp -s 0/0 --sport 1024:65535 -d $SERVER_IP --dport 53
-m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -p udp -s $SERVER_IP --sport 53 -d 0/0 --dport 1024:65535
-m state --state ESTABLISHED -j ACCEPT
iptables -A INPUT -p udp -s 0/0 --sport 53 -d $SERVER_IP --dport 53 -m state
iptables -A OUTPUT -p udp -s $SERVER_IP --sport 53 -d 0/0 --dport 53 -m
state --state ESTABLISHED -j ACCEPT
iptables -A INPUT -p tcp -s 0/0 --sport 1024:65535 -d $SERVER_IP --dport 53
-m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -p tcp -s $SERVER_IP --sport 53 -d 0/0 --dport 1024:65535
-m state --state ESTABLISHED -j ACCEPT
iptables -A INPUT -p tcp -s 0/0 --sport 53 -d $SERVER_IP --dport 53 -m state
iptables -A OUTPUT -p tcp -s $SERVER_IP --sport 53 -d 0/0 --dport 53 -m
state --state ESTABLISHED -j ACCEPT

I still have the same effect.

Running the following shows that the system is refusing the connection.
/usr/sbin/tcpdump -X port 53

[root at fc9 named]# /usr/sbin/tcpdump -X port 53
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes
21:39:38.512926 IP aix.sparish.local.52686 > fc9.sparish.local.domain:
46304+ PTR? (43)
        0x0000:  4500 0047 ac22 0000 1e11 6ccd c0a8 0134  E..G."....l....4
        0x0010:  c0a8 0132 cdce 0035 0033 7c2c b4e0 0100  ...2...5.3|,....
        0x0020:  0001 0000 0000 0000 0235 3001 3103 3136  .........50.1.16
        0x0030:  3803 3139 3207 696e 2d61 6464 7204 6172  8.192.in-addr.ar
        0x0040:  7061 0000 0c00 01                        pa.....
21:39:38.519048 IP fc9.sparish.local.domain > aix.sparish.local.52686: 46304
Refused- 0/0/0 (43)
        0x0000:  4500 0047 0000 4000 4011 b6ef c0a8 0132  E..G.. at .@......2
        0x0010:  c0a8 0134 0035 cdce 0033 fc26 b4e0 8105  ...4.5...3.&....
        0x0020:  0001 0000 0000 0000 0235 3001 3103 3136  .........50.1.16
        0x0030:  3803 3139 3207 696e 2d61 6464 7204 6172  8.192.in-addr.ar
        0x0040:  7061 0000 0c00 01                        pa.....

Any help would be welcome


Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

<div>I have Fedora 9 installed and would like to use it as the DNS system in the house. </div>
<div>The setup is as follows</div>
<div>options {<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; listen-on port 53 { <a href=""></a>; };<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; listen-on-v6 port 53 { ::1; };<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; directory&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;/var/named&quot;;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; dump-file&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &quot;/var/named/data/cache_dump.db&quot;;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; statistics-file &quot;/var/named/data/named_stats.txt&quot;;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; memstatistics-file &quot;/var/named/data/named_mem_stats.txt&quot;;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; allow-query&nbsp;&nbsp;&nbsp;&nbsp; { localhost; };<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; recursion yes;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; forwarders {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a href=""></a>;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a href=""></a>;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; };<br>};</div>
<div>logging {<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; channel default_debug {<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; file &quot;data/named.run&quot;;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; severity dynamic;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; };<br>};</div>
<div>zone &quot;.&quot; IN {<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; type hint;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; file &quot;<a href="http://named.ca">named.ca</a>&quot;;<br>};<br></div>
<div><br>include &quot;/etc/named.rfc1912.zones&quot;;</div>
<div>zone &quot;home.local&quot; {<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; type master;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; file &quot;/var/named/home.local.hosts&quot;;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; };</div>
<div><br>zone &quot;1.168.192.in-addr.arpa&quot; {<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; type master;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; file &quot;1.168.192.in-addr.arpa.zone&quot;;<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; allow-update { key &quot;rndckey&quot;; };<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; notify yes;<br></div>
<div>I have the files in /var/named setup and configured. From the DNS system I can type </div>
<div>nslookup 43p and get the following</div>
<div>[root at fc9 named]# vi /etc/named.conf<br>[root at fc9 named]# nslookup 43p<br>Server:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a href=""></a><br>Address:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a href=""></a></div>
<div>Name:&nbsp;&nbsp; 43p.home.local<br>Address: <a href=""></a></div>
<div>From a windows system&nbsp;I get the following</div>
<div>C:\Users\dalan&gt;nslookup 43p<br>Server:&nbsp; UnKnown<br>Address:&nbsp; <a href=""></a></div>
<div>*** UnKnown can&#39;t find 43p: Query refused</div>
<div>From the AIX system I get</div>
<div>(43p-aix) [dalan] nslookup 43p<br>*** Can&#39;t find server name for address refused<br>*** Default servers are not available<br>(43p-aix) [dalan]<br></div>
<div>I have shut off the firewall and SE-Linux on the Fedora system. I&#39;m not sure why the fedora system is blocking/refusing the request coming from another system.</div>
<div>I even put the following entries in iptables.</div>
<div>SERVER_IP=&quot;<a href=""></a>&quot;<br>iptables -A INPUT -p udp -s 0/0 --sport 1024:65535 -d $SERVER_IP --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT<br>iptables -A OUTPUT -p udp -s $SERVER_IP --sport 53 -d 0/0 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT<br>
iptables -A INPUT -p udp -s 0/0 --sport 53 -d $SERVER_IP --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT<br>iptables -A OUTPUT -p udp -s $SERVER_IP --sport 53 -d 0/0 --dport 53 -m state --state ESTABLISHED -j ACCEPT</div>

<div>iptables -A INPUT -p tcp -s 0/0 --sport 1024:65535 -d $SERVER_IP --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT<br>iptables -A OUTPUT -p tcp -s $SERVER_IP --sport 53 -d 0/0 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT<br>
iptables -A INPUT -p tcp -s 0/0 --sport 53 -d $SERVER_IP --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT<br>iptables -A OUTPUT -p tcp -s $SERVER_IP --sport 53 -d 0/0 --dport 53 -m state --state ESTABLISHED -j ACCEPT</div>

<div>I still have the same effect.</div>
<div>Running the following shows that the system is refusing the connection.</div>
<div>/usr/sbin/tcpdump -X port 53</div>
<div><br>[root at fc9 named]# /usr/sbin/tcpdump -X port 53<br>tcpdump: verbose output suppressed, use -v or -vv for full protocol decode<br>listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes<br>21:39:38.512926 IP aix.sparish.local.52686 &gt; fc9.sparish.local.domain: 46304+ PTR? (43)<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0x0000:&nbsp; 4500 0047 ac22 0000 1e11 6ccd c0a8 0134&nbsp; E..G.&quot;....l....4<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0x0010:&nbsp; c0a8 0132 cdce 0035 0033 7c2c b4e0 0100&nbsp; ...2...5.3|,....<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0x0020:&nbsp; 0001 0000 0000 0000 0235 3001 3103 3136&nbsp; .........50.1.16<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0x0030:&nbsp; 3803 3139 3207 696e 2d61 6464 7204 6172&nbsp; <a href="http://8.192.in-addr.ar">8.192.in-addr.ar</a><br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0x0040:&nbsp; 7061 0000 0c00 01&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; pa.....<br>21:39:38.519048 IP fc9.sparish.local.domain &gt; aix.sparish.local.52686: 46304 Refused- 0/0/0 (43)<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0x0000:&nbsp; 4500 0047 0000 4000 4011 b6ef c0a8 0132&nbsp; <a href="mailto:E..G.. at .@......2">E..G.. at .@......2</a><br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0x0010:&nbsp; c0a8 0134 0035 cdce 0033 fc26 b4e0 8105&nbsp; ...4.5...3.&amp;....<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0x0020:&nbsp; 0001 0000 0000 0000 0235 3001 3103 3136&nbsp; .........50.1.16<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0x0030:&nbsp; 3803 3139 3207 696e 2d61 6464 7204 6172&nbsp; <a href="http://8.192.in-addr.ar">8.192.in-addr.ar</a><br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 0x0040:&nbsp; 7061 0000 0c00 01&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; pa.....<br></div>
<div>Any help would be welcome</div>
