4 ms·
Well, because he doesn't want to be inline for non-.internal DNS queries.
by ptomato 5y ago
Well, because he doesn't want to be inline for non-.internal DNS queries.
- throwaway823882 5y agoYou can technically add an iptables match rule to only forward DNS packets whose contents match a ".internal" DNS query, but it sounds like a recipe for disaster. It would be better if they wrote an actual iptables protocol filter for DNS (assuming one doesn't exist) but that's so much work for so little benefit.
- ptomato 5y agosure, but that's why BPF is so great; I'd guess a reasonable program that assumes port 53, parses the packet enough to look at the first question and compare domain against .internal and then rewrites address + updates checksum is maybe... 300-400 LOC? can probably get a bit fancier, but it shouldn't be too painful to write and will execute plenty fast enough.