Hi, I performed a show of the rules and looked at what can refer to the blocking of the dns port. I looked carefully at the chains, but found it difficult to interpret the various blocks. Hereβs how:
Shorewall 5.1.10.2 filter Table at neth7.internal2.lan - Tue Oct 1 07:20:55 CEST 2019
Counters reset Mon Sep 30 18:37:37 CEST 2019
Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
6757K 742M br0_in all β br0 * 0.0.0.0/0 0.0.0.0/0
701K 715M ACCEPT all β lo * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type ANYCAST
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type MULTICAST
0 0 LOG all β * * 0.0.0.0/0 0.0.0.0/0 limit: up to 1/sec burst 10 mode srcip LOG flags 0 level 6 prefix βShorewall:INPUT:REJECT:β
0 0 reject all β * * 0.0.0.0/0 0.0.0.0/0 [goto]
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 br0_fwd all β br0 * 0.0.0.0/0 0.0.0.0/0
0 0 ppp+_fwd all β ppp+ * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type ANYCAST
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type MULTICAST
0 0 LOG all β * * 0.0.0.0/0 0.0.0.0/0 limit: up to 1/sec burst 10 mode srcip LOG flags 0 level 6 prefix βShorewall:FORWARD:REJECT:β
0 0 reject all β * * 0.0.0.0/0 0.0.0.0/0 [goto]
Chain OUTPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
698K 18G ACCEPT all β * br0 0.0.0.0/0 0.0.0.0/0
701K 715M ACCEPT all β * lo 0.0.0.0/0 0.0.0.0/0
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type ANYCAST
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type MULTICAST
0 0 LOG all β * * 0.0.0.0/0 0.0.0.0/0 limit: up to 1/sec burst 10 mode srcip LOG flags 0 level 6 prefix βShorewall:OUTPUT:REJECT:β
0 0 reject all β * * 0.0.0.0/0 0.0.0.0/0 [goto]
Chain br0_fwd (1 references)
pkts bytes target prot opt in out source destination
0 0 dynamic all β * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW,ESTABLISHED,UNTRACKED
0 0 smurfs all β * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW,UNTRACKED
0 0 ACCEPT udp β * br0 0.0.0.0/0 0.0.0.0/0 udp dpts:67:68
0 0 tcpflags tcp β * * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all β * br0 127.0.0.1 0.0.0.0/0
0 0 ACCEPT all β * br0 192.168.17.0/24 0.0.0.0/0
0 0 ACCEPT all β * br0 192.168.19.0/24 0.0.0.0/0
0 0 ACCEPT all β * br0 192.168.3.0/24 0.0.0.0/0
0 0 ACCEPT all β * br0 192.168.5.0/24 0.0.0.0/0
0 0 net2loc all β * br0 0.0.0.0/0 127.0.0.1
0 0 net2loc all β * br0 0.0.0.0/0 192.168.17.0/24
0 0 net2loc all β * br0 0.0.0.0/0 192.168.19.0/24
0 0 net2loc all β * br0 0.0.0.0/0 192.168.3.0/24
0 0 net2loc all β * br0 0.0.0.0/0 192.168.5.0/24
0 0 ACCEPT all β * br0 0.0.0.0/0 0.0.0.0/0
Chain br0_in (1 references)
pkts bytes target prot opt in out source destination
6757K 742M dynamic all β * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW,ESTABLISHED,UNTRACKED
14497 2339K smurfs all β * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW,UNTRACKED
110 38763 ACCEPT udp β * * 0.0.0.0/0 0.0.0.0/0 udp dpts:67:68
6729K 737M tcpflags tcp β * * 0.0.0.0/0 0.0.0.0/0
0 0 loc2fw all β * * 127.0.0.1 0.0.0.0/0
0 0 loc2fw all β * * 192.168.17.0/24 0.0.0.0/0
0 0 loc2fw all β * * 192.168.19.0/24 0.0.0.0/0
6706K 674M loc2fw all β * * 192.168.3.0/24 0.0.0.0/0
0 0 loc2fw all β * * 192.168.5.0/24 0.0.0.0/0
50868 69M ACCEPT all β * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
0 0 ACCEPT icmp β * * 0.0.0.0/0 0.0.0.0/0 icmptype 8 /* Ping /
0 0 ACCEPT tcp β * * 0.0.0.0/0 0.0.0.0/0 multiport dports 110,143,4190,993,995,80,443,980,25,465,587,2222 / dovecot, httpd, httpd-admin, postfix, sshd */
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type ANYCAST
6 1195 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type MULTICAST
0 0 LOG all β * * 0.0.0.0/0 0.0.0.0/0 limit: up to 1/sec burst 10 mode srcip LOG flags 0 level 6 prefix βShorewall:net2fw:DROP:β
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0
Chain dynamic (3 references)
pkts bytes target prot opt in out source destination
0 0 DROP all β * * 66.249.64.106 0.0.0.0/0
Chain loc2fw (5 references)
pkts bytes target prot opt in out source destination
6692K 671M ACCEPT all β * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
0 0 ACCEPT icmp β * * 0.0.0.0/0 0.0.0.0/0 icmptype 8 /* Ping /
8197 1826K ACCEPT udp β * * 0.0.0.0/0 0.0.0.0/0 multiport dports 5353,123 / avahi-daemon, chronyd /
6 360 ACCEPT tcp β * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:631 / cups /
0 0 ACCEPT udp β * * 0.0.0.0/0 0.0.0.0/0 udp dpt:631 / cups /
0 0 ACCEPT tcp β * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:53 / dnsmasq /
2265 178K ACCEPT udp β * * 0.0.0.0/0 0.0.0.0/0 multiport dports 53,67,69 / dnsmasq /
1262 80768 ACCEPT tcp β * * 0.0.0.0/0 0.0.0.0/0 multiport dports 110,143,4190,993,995,80,443,980,19999 / dovecot, httpd, httpd-admin, netdata /
476 74584 ACCEPT udp β * * 0.0.0.0/0 0.0.0.0/0 multiport dports 137,138 / nmb /
21 1304 ACCEPT tcp β * * 0.0.0.0/0 0.0.0.0/0 multiport dports 25,465,587,139,445,2222 / postfix, smb, sshd */
2089 133K DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type ANYCAST
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type MULTICAST
65 5636 LOG all β * * 0.0.0.0/0 0.0.0.0/0 limit: up to 1/sec burst 10 mode srcip LOG flags 0 level 6 prefix βShorewall:loc2fw:REJECT:β
65 5636 reject all β * * 0.0.0.0/0 0.0.0.0/0 [goto]
Chain logdrop (0 references)
pkts bytes target prot opt in out source destination
0 0 LOG all β * * 0.0.0.0/0 0.0.0.0/0 limit: up to 1/sec burst 10 mode srcip LOG flags 0 level 6 prefix βShorewall:logdrop:DROP:β
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0
Chain logreject (0 references)
pkts bytes target prot opt in out source destination
0 0 LOG all β * * 0.0.0.0/0 0.0.0.0/0 limit: up to 1/sec burst 10 mode srcip LOG flags 0 level 6 prefix βShorewall:logreject:REJECT:β
0 0 reject all β * * 0.0.0.0/0 0.0.0.0/0
Chain net2loc (5 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all β * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type ANYCAST
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type MULTICAST
0 0 LOG all β * * 0.0.0.0/0 0.0.0.0/0 limit: up to 1/sec burst 10 mode srcip LOG flags 0 level 6 prefix βShorewall:net2loc:DROP:β
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0
Chain ppp+_fwd (1 references)
pkts bytes target prot opt in out source destination
0 0 sfilter all β * ppp+ 0.0.0.0/0 0.0.0.0/0 [goto]
0 0 dynamic all β * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW,ESTABLISHED,UNTRACKED
0 0 tcpflags tcp β * * 0.0.0.0/0 0.0.0.0/0
Chain reject (5 references)
pkts bytes target prot opt in out source destination
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match src-type BROADCAST
0 0 DROP all β * * 224.0.0.0/4 0.0.0.0/0
0 0 DROP 2 β * * 0.0.0.0/0 0.0.0.0/0
1 40 REJECT tcp β * * 0.0.0.0/0 0.0.0.0/0 reject-with tcp-reset
64 5596 REJECT udp β * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
0 0 REJECT icmp β * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-unreachable
0 0 REJECT all β * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
Chain sfilter (1 references)
pkts bytes target prot opt in out source destination
0 0 LOG all β * * 0.0.0.0/0 0.0.0.0/0 limit: up to 1/sec burst 10 mode srcip LOG flags 0 level 6 prefix βShorewall:sfilter:DROP:β
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0
Chain sha-lh-216b87e5116e9bc7d3cb (0 references)
pkts bytes target prot opt in out source destination
Chain sha-rh-3f4117dcfe01d5a72b83 (0 references)
pkts bytes target prot opt in out source destination
Chain shorewall (0 references)
pkts bytes target prot opt in out source destination
0 0 all β * * 0.0.0.0/0 0.0.0.0/0 recent: SET name: %CURRENTTIME side: source mask: 255.255.255.255
Chain smurfs (2 references)
pkts bytes target prot opt in out source destination
61 22258 RETURN all β * * 0.0.0.0 0.0.0.0/0
0 0 DROP all β * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match src-type BROADCAST
0 0 DROP all β * * 224.0.0.0/4 0.0.0.0/0
Chain tcpflags (3 references)
pkts bytes target prot opt in out source destination
0 0 DROP tcp β * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x3F/0x29
0 0 DROP tcp β * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x3F/0x00
0 0 DROP tcp β * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x06/0x06
0 0 DROP tcp β * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x05/0x05
0 0 DROP tcp β * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x03/0x03
0 0 DROP tcp β * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x19/0x09
0 0 DROP tcp β * * 0.0.0.0/0 0.0.0.0/0 tcp spt:0 flags:0x17/0x02