3 ms·
I solve this with a DNS based firewall. Essentially it's just DNS filtering on steriods. You start with an empty (or preseeded) ipset, and a firewall rule that
by DistractionRect 4y ago
I solve this with a DNS based firewall.
Essentially it's just DNS filtering on steriods. You start with an empty (or preseeded) ipset, and a firewall rule that says to reject/drop all outbound traffic if the destination isn't in the ipset. Dnsmasq is setup as the default dns provider in DHCP, and it's setup to add all resolved IPs to the ipset (with an expiration so stale entries get removed).
Then it's just DNS filtering per the usual. DoH, DoQUIC, DoT, etc don't work as their hardcoded IPs are blocked by default, and DNS filtering knocks out domain resolution of the endpoints. Even if an alternate resolver is allowed through the firewall, none of it's responses get into the ipset, so it's still broken (and is a sign I need to update the DNS filter).
Works a treat on my IoT devices
- BLKNSLVR 4y agoI really like the concept of this approach, I'd say it's worth writing a blog post / article describing the process and details so others can duplicate it.
- afraca 4y agoThis is very very similar to something developed by SIDN labs called "DNS Resolution Required", you can read the blog post here: https://www.sidnlabs.nl/en/news-and-blogs/dns-resolution-required-can-help-make-the-internet-safer https://www.sidnlabs.nl/en/news-and-blogs/dns-resolution-req...