Iptables blocking access to DNS server

Iptables blocking access to DNS server

 

hi, i hv setup a OpenVPN with Pihole on a Raspberry pi running Ubuntu 20.04 64bit on my LAN. Everything works perfectly – i can connect to the vpn and pihole does it job filtering ads. i could even manually point other pc’s DNS to the Raspberry IP address to use its Pihole ad blocking. Until i apply the iptables below: Then i could no longer use the Pihole if im not connected to the vpn. I try adding POSTROUTING from 192.168.1.13 to 10.8.0.1 but it hangs. Luckily could access to the Raspberry after cycle the power. Please advice on how we could use the Pihole’s DNS even if we are not connected to the vpn. Raspberry Pi : 192.168.1.13 OpenVPN TUN: 10.8.0.1 Thank you. Code: # Generated by iptables-save v1.8.4 on Thu Jul 16 13:32:36 2020 *mangle :PREROUTING ACCEPT [142:12092] :INPUT ACCEPT [142:12092] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [113:16556] :POSTROUTING ACCEPT [113:16556] COMMIT # Completed on Thu Jul 16 13:32:36 2020 # Generated by iptables-save v1.8.4 on Thu Jul 16 13:32:36 2020 *nat :PREROUTING ACCEPT [0:0] :INPUT ACCEPT [0:0] :OUTPUT ACCEPT [0:0] :POSTROUTING ACCEPT [0:0] -A POSTROUTING -s 10.8.0.0/24 ! -d 10.8.0.0/24 -j SNAT –to-source 192.168.1.13 COMMIT # Completed on Thu Jul 16 13:32:36 2020 # Generated by iptables-save v1.8.4 on Thu Jul 16 13:32:36 2020 *filter :INPUT DROP [3:108] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [113:16556] -A INPUT -i lo -j ACCEPT -A INPUT -m state –state RELATED,ESTABLISHED -j ACCEPT -A INPUT -p tcp -m tcp –tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP -A INPUT -p tcp -m tcp ! –tcp-flags FIN,SYN,RST,ACK SYN -m state –state NEW -j DROP -A INPUT -p tcp -m tcp –tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP -A INPUT -i tun0 -p tcp -m tcp –dport 53 -j ACCEPT -A INPUT -i tun0 -p udp -m udp –dport…

 

Previous link folders to other partition
Next (Browser: Brave) backup
 

About author

You might also like

Ubuntu Dsicussions 0 Comments

How to restrict Zoom access to files?

Hello, I’m using the zoom-client snap. I would like to prevent Zoom being able to access my files, so I disconnected the “home” interface with the following command: Code: snap

Ubuntu Dsicussions 0 Comments

LUBUNTU How to disable nouveau kernel driver to install proprietary drivers ?

My system is offline and wait to install latest nvidia proprietary driver, but see that need to disable nouveau driver. I have disabled nouveau driver, but when starting nvidia driver

Ubuntu Dsicussions 0 Comments

[ubuntu] My 20.04 fresh installed ubuntu is totally slow

Hello, I have installed ubuntu 20.04 next to my Windows10. After the boot screen where I chose Ubuntu I have to wait more than two minutes to get the loaded

0 Comments

No Comments Yet!

You can be first to comment this post!

Leave a Reply