Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

IPsec basic Q

Status
Not open for further replies.

Niksen

IS-IT--Management
Apr 25, 2002
211
EU
On my DC internally i get events from DNS saying
"The DNS server encountered an invalid domain name in a packet from 200.216.68.42. The packet is rejected."
my subnet is 192.168.0.0/24 so i dont see how these packets can reach the DC.
i want to set up IPsec to block all DNS packets from outside 192.168.0.0/24. Its easy to make a rule that allows all 192.168.0.0/24 to request on port 53 to "my own ip" on the DC.
but if i make another rule saying "block" 0.0.0.0 ....
well how do i do that, if i block all, 192.168.0.0/24 will not get through ?
usually on firewalls the rules are read from top, until a matching filter is found.
will ipsec work the same way ?

I hope i have explained clearly.

MVH Nicolai
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top