On Tue, Jul 15, 2008 at 11:55 AM, nate <centos at linuxpowered.net> wrote: > Sean Carolan wrote: > >> What is confusing me is why my iptables rule is not working correctly. >> TCPdump shows that the source is correct. Any ideas? > > try blocking tcp as well, most name servers listen on both tcp and > udp. I do have a rule for blocking TCP, forgot to mention that. You can see from my tcpdump output above that the inbound packet is UDP though. I wonder why iptables doesn't block it even with this rule?