NetFilter
[Top] [All Lists]

RE: Accept DNS Suffix

To: <netfilter@lists.netfilter.org>
Subject: RE: Accept DNS Suffix
From: "Rob Sterenborg" <rob@sterenborg.info>
Date: Tue, 20 Mar 2007 19:13:41 +0100
Delivered-to: sp-com-lists@consult.net
Delivered-to: netfilter-list1@securepoint.com
In-reply-to: <000f01c76a83$f8563dd0$6f05b00a@au.schpac.local>
List-archive: </pipermail/netfilter>
List-help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-id: General discussion and user questions <netfilter.lists.netfilter.org>
List-post: <mailto:netfilter@lists.netfilter.org>
List-subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
Sender: netfilter-bounces@lists.netfilter.org
Thread-index: AcdqhD3lgN/iJ8LCRLGaPvFynaWUkQAlv5Ag
> I currently have an ISP that has multiple address ranges that I wish
> to accept in my iptables ruleset. Is it possible for me to use the
> DNS Suffix instead of the actual ip as they are currently dynamically
> assigned. e.g. iptables -s nsw.bigpond.net.au   (current assigned
> address is cpe-203-45-103-100.nsw.bigpond.net.au).

AFAIK: no.
An iptables rule will do a DNS lookup for a *hostname*, but only once:
when the rule is created.


Grts,
Rob



<Prev in Thread] Current Thread [Next in Thread>