4 ms·
Having to do a DNS lookup for each firewall rule is going to suck. Not to mention blackholing traffic when cached DNS replies are out of sync with the actual I
by iptrans 5y ago
Having to do a DNS lookup for each firewall rule is going to suck. Not to mention blackholing traffic when cached DNS replies are out of sync with the actual IP.
- vetinari 5y agoI can see that there is a user-space daemon, that watches TTLs in the resolved DNS records and if they change, updates an corresponding ip set in the firewall.
- admax88qqq 5y agoDoesn't have to be DNS, could be any sort of cache on the router that updates when new hosts come online or the prefix changes. Plus blackholing temporarily due to a stale cache is better than blackholing permanently due to a stale rule pointing to an old IP.
- blibble 5y agohow do client firewalls deal with that? the don't know the router lost its connection