Skip to main content

Thread: iptables rule


hello,

have nagios monitoring server dns query each service check. have 2500 service checks , because of there 20000 dns queries in 5 minutes.

problem queries on ipv6 , on ipv4. have disabled regarding ipv6 in kernel, services.. have read queries ipv6 address through ipv4 protocol, how resolver works kernel version. decided make iptables rule drop aaaa requests on output not stress dns server.

here how see dns queries nagios server:
[root@sums011 ~]# tcpdump | grep aaaa
tcpdump: verbose output suppressed, use -v or -vv full protocol decode
listening on eth0, link-type en10mb (ethernet), capture size 96 bytes
10:18:49.177033 ip sums011.example.com.36699 > suds002.example.com.domain: 16939+ aaaa? suas005.example.com. (43)
sums011 monitoring server
suds002 dns server
suas005 name requested resolving

if can tell me rule add iptables file drops every package contains aaaa grateful.
if have other ideas on how solve problem i'll glad.



Forum The Ubuntu Forum Community Ubuntu Specialised Support Ubuntu Servers, Cloud and Juju Server Platforms [all variants] iptables rule


Ubuntu

Comments

Popular posts from this blog

Warning, the Safe Path is not accessible vm3 - Joomla! Forum - community, help and support

2.5.28 to 3.4.1---Download of update package failed - Joomla! Forum - community, help and support

Your host needs to use PHP 5.3.10 or higher to run this vers - Joomla! Forum - community, help and support