Technical data

4. Packages
YADIFA_ALLOW_QUERY_N
YADIFA_ALLOW_QUERY_x Sets the IP addresses and nets that are allowed to access YAD-
IFA. This setting will be used by YADIFA to configure fli4l’s packet filter accordingly
and to generate the configuration files for YADIFA. By the prefix “!” acces to YADIFA
is denied for the IP address or network in question.
The fli4l packet filter will be configured in a way that all nets allowed in this variable
and those for the zones are joined in an ipset list (yadifa-allow-query). A differentiation
on zones is not possible for the packet filter. In addition all IP addressesand nets from
this global setting whose access is denied will be added to the list. So you can’t reenable
access later on.
YADIFA_SLAVE_ZONE_N Specifies the number of slave DNS zones YADIFA should take
care of.
YADIFA_SLAVE_ZONE_x The name of the slave DNS zone.
OPT_YADIFA_SLAVE_ZONE_USE_DNSMASQ_ZONE_DELEGATION Activates (=’yes’)
or deactivates (=’no’) the dnsmasq zone delegation only for the slave zone.
YADIFA_SLAVE_ZONE_x_MASTER The IP address of the DNS master server with an
optional port number.
YADIFA_SLAVE_ZONE_x_ALLOW_QUERY_N
YADIFA_SLAVE_ZONE_x_ALLOW_QUERY_x Specifies IP addresses and nets for which
access to this YADIFA DNS zone is allowed. This can be used to limit access to certain
DNS zones even more. YADIFA uses this setting to generate its configuration files.
By the prefix “!” acces to YADIFA is denied for the IP address or network in question.
4.6. DSL - DSL over PPPoE, Fritz!DSL and PPTP
fli4l supports DSL in three different variants:
PPPoE (external DSL-modems connected over ethernet using pppoe)
PPTP (external DSL-modems connected over ethernet using pptp)
Fritz!DSL (DSL over DSL-adapters manufactured by AVM)
You can choose only one of these options, simultaneous operation isn’t possible yet. The
configuration for all variants is similar, so the general parameters are described at first and
then the special options for the individual variants will be discussed. DSL-access is handled
by imond as a circuit. Therefore it is necessary to activate imond by setting (see START_IMOND
(Page 69)) to 'yes'.
104