diff options
author | Jan Engelhardt <jengelh@medozas.de> | 2009-11-18 00:00:37 +0100 |
---|---|---|
committer | Jan Engelhardt <jengelh@medozas.de> | 2009-11-18 00:01:23 +0100 |
commit | 1bd2f0a20596e47c082c2415369a209ed1b329f6 (patch) | |
tree | a4907f96f03620a9ae0675602deacfd645c03101 /iptables.8.in | |
parent | 7573631fa9f6f15b28a13cc5d22f2a446f69fd64 (diff) |
doc: name resolution clarification
Sometimes there are users who wonder about when name resolutions/DNS
queries are done, so let's add that for completeness.
Signed-off-by: Jan Engelhardt <jengelh@medozas.de>
Diffstat (limited to 'iptables.8.in')
-rw-r--r-- | iptables.8.in | 8 |
1 files changed, 5 insertions, 3 deletions
diff --git a/iptables.8.in b/iptables.8.in index 928f46a9..d29deb2e 100644 --- a/iptables.8.in +++ b/iptables.8.in @@ -239,9 +239,11 @@ option is omitted. .TP [\fB!\fP] \fB\-s\fP, \fB\-\-source\fP \fIaddress\fP[\fB/\fP\fImask\fP][\fB,\fP\fI...\fP] Source specification. \fIAddress\fP -can be either a network name, a hostname (please note that specifying -any name to be resolved with a remote query such as DNS is a really bad idea), -a network IP address (with \fB/\fP\fImask\fP), or a plain IP address. +can be either a network name, a hostname, a network IP address (with +\fB/\fP\fImask\fP), or a plain IP address. Hostnames will +be resolved once only, before the rule is submitted to the kernel. +Please note that specifying any name to be resolved with a remote query such as +DNS is a really bad idea. The \fImask\fP can be either a network mask or a plain number, specifying the number of 1's at the left side of the network mask. |