Boston Linux & Unix (BLU) Home | Calendar | Mail Lists | List Archives | Desktop SIG | Hardware Hacking SIG
Wiki | Flickr | PicasaWeb | Video | Maps & Directions | Installfests | Keysignings
Linux Cafe | Meeting Notes | Blog | Linux Links | Bling | About BLU

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

iptables question



On 10/23/2009 04:13 PM, Dave Peters wrote:
> Is there anyway to use iptables blocking domain name not IP address?
> 
> Example to block hotmail.com.
> 
> I tried this iptables -A FORWARD -d hotmail.com -j REJECT and it won't work.

No.  iptables will just do a DNS lookup on that and convert it to an ip
address, then add a rule.  The problem is that high-volume, load-balanced
domains won't have a single ip address.  And it certainly wouldn't work to
try and block anything under the hotmail domain.

What is it that you're trying to do?  There might be an easier way...

Matt






BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org