Ben Therode wrote:
DNS and it's ilk normally operate over UDP, don't they? They will fall back to a TCP connection if they cannot get a UDP connection through. Explicitly opening port 53 for tcp is only half of your problem, you needed to open it up for udp as well.Ugh, it looks like pf *WAS* blocking port 53.
Despite specifically telling pf.conf:
pass out quick on rl0 proto tcp from any to any port 53 and for good measure:
pass in quick on rl0 proto tcp from any to any port 53
Gaby
-- Ha! Ha! Ha! Dislocation... - Phil Ken Sebben
gaby_(_at_)_vanhegan_(_dot_)_net http://vanhegan.net