[ ipcop-Bugs-3516627 ] dnsmasq needs setting for upstream dns for local domain

SourceForge.net <[email protected]>
Newsgroups gmane.comp.security.ipcop.devel
Message-ID <[email protected]>
Bugs item #3516627, was opened at 2012-04-10 13:32
Message generated for change (Tracker Item Submitted) made by dhowdeshell
You can respond by visiting: 
https://sourceforge.net/tracker/?func=detail&atid=428516&aid=3516627&group_id=40604

Please note that this message will contain a full copy of the comment thread,
including the initial issue submission, for this request,
not just the latest update.
Category: General
Group: 2.0.0
Status: Open
Resolution: None
Priority: 5
Private: No
Submitted By: Don Howdeshell (dhowdeshell)
Assigned to: Nobody/Anonymous (nobody)
Summary: dnsmasq needs setting for upstream dns for local domain

Initial Comment:
This is my first entry on sourceforge and I'm not familiar with etiquette, so please forgive newbie mistakes.

A bugfix listed here https://sourceforge.net/tracker/index.php?func=detail&aid=2806823&group_id=40604&atid=428516 changes calls to the DNSMASQ daemon to use the `--local=$DOMAINNAME` switch that causes the service not to pass DNS queries to upstream servers for the local domain.

While this is a good default, some of us have our DNS configured properly with external servers and this option causes that external DNS to stop working within our network.  

I've confirmed that removing that option from /etc/rc.d/rc.dnsmasq OR commenting out `except-interface=wan-1' in /var/ipcop/dhcp/dnsmasq.conf both result in IPCop using upstream DNS for the local domain.  

An appropriate place to put such an option might be in /var/ipcop/dhcp/dnsmasq.local (since it is not supposed to be overwritten by updates) and when rc.dnsmasq loads the daemon it could parse that file to look for a 'always_use_upstream_dns=1' option.  

I don't know how these sort of things get worked out, but I could supply a patch file for rc.dnsmasq if that is what is expected. 


----------------------------------------------------------------------

You can respond by visiting: 
https://sourceforge.net/tracker/?func=detail&atid=428516&aid=3516627&group_id=40604

------------------------------------------------------------------------------
Better than sec? Nothing is better than sec when it comes to
monitoring Big Data applications. Try Boundary one-second 
resolution app monitoring today. Free.
http://p.sf.net/sfu/Boundary-dev2dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.