3 ms·
because firewalls filter at the IP/port level, not at DNS level
by luch 4y ago
because firewalls filter at the IP/port level, not at DNS level
- Hikikomori 4y agoThere are firewalls with those features.
- tecleandor 4y agoDepending on what you want to do it's not applicable. You can only easily guess the domain from HTTP connections and maybe from other tcp stuff if you have TLS + SNI in front. For example, you can't guess the target domain for an ssh connection.
- Hikikomori 4y agoNo. They do a dns lookup and allow the IP addresses returned.
- efdee 4y agoBut some routers will let you set a rule on a domain name. They will then resolve that domain name to an IP and use that internally, and do periodic lookups to refresh the IP they're referring to.
- tecleandor 4y agoThing is, if you're sharing that IP with several different domains, then you can't route properly :(
- worldsavior 4y agoUse one domain.
- worldsavior 4y agoThe DNS server should return the IP.