Technical data
3. Base configuration
PF_PREROUTING_CT_N PF_PREROUTING_CT_x PF_PREROUTING_CT_x_COMMENT
List of rules that describe which incoming packets are associated with conntrack helpers
by the router.
PF_OUTPUT_CT_ACCEPT_DEF If this variable is set to ‘yes’, default rules are generated
that are necessary for proper functioning of the router. By default, you should use ‘yes’
here.
PF_OUTPUT_CT_N PF_OUTPUT_CT_x PF_OUTPUT_CT_x_COMMENT
List of rules that describe which packets generated on the router are associated with
conntrack helpers by the router.
3.11. Domain configuration
Windows PCs exhibit a somewhat annoying behaviour: If a DNS server is needed and config-
ured at the Windows system, the server is queried regularly (every five minutes) – even if you
don’t work at the PC!
If you configured an Internet DNS server at your Windows PC, your next bill might become
quite expensive :-(
If you don’t already run a DNS server in your LAN, this problem can be solved by enabling
the DNS server of your fli4l router. The DNS server software used is DNSMASQ.
Before you start configuring your DNS, however, you should give careful consideration to
the domain name and the names of the PCs in your network. The domain name you use will
not be visible in the Internet. Therefore, you are free to choose any domain name you like.
Additionally, each of your PCs in the LAN has to have a name assigned. These names have
to be known by the fli4l router.
DOMAIN_NAME Default Setting: DOMAIN_NAME=’lan.fli4l’
You can freely choose any domain name as this local domain is not visible in the Inter-
net. However, you should avoid choosing a name that may exist in the Internet (e.g.
somewhat.com) because you won’t be able to access that Internet domain.
DNS_FORWARDERS Default Setting: DNS_FORWARDERS=”
This variable contains the address of your Internet provider’s DNS server if you want
your fli4l router to route Internet traffic. The fli4l router will forward all DNS queries
which it is not able to answer on its own to the address in this variable.
You can specify more than one DNS forwarder by separating the addresses by blanks.
It is also possible to specify a port number for each DNS forwarder address which is then
to be separated from the address by a colon. However, in this case it is required to set
OPT_DNS=’yes’ (Page 94) (Package dns_dhcp (Page 93)), and you are not allowed to use
any of the various *_USEPEERDNS options.
Beware: Even if
• PPPOE_USEPEERDNS (Page 105),
• ISDN_CIRC_x_USEPEERDNS (Page 151) or
• DHCPCLIENT_x_USEPEERDNS (Page 93)
68










