3 ms·
I made it a point to NAT redirect all outbound requests to UDP 53 in our enterprise back to our enterprise DNS server. It would sometimes piss off our engineers
by AviationAtom 3y ago
I made it a point to NAT redirect all outbound requests to UDP 53 in our enterprise back to our enterprise DNS server. It would sometimes piss off our engineers, when they realized 8.8.8.8 was somehow resolving our internal DNS names, but if they came to us and nicely explained their use-case then we excluded them from the NAT rule.
- groestl 3y agoGreat when you debug something for ages, just to find out your company's DNS setup is broken. Because it can't be DNS, right? /s
- AviationAtom 3y agoCompliance sucks, but it's required. I didn't make up the rules, just implemented and enforced them.
- groestl 3y agoSorry, my snarkiness was not meant personal, I know you're not to blame :)
- watersb 3y agoI had add port 53 NAT redirect to my home network. Kindle Fire tablet has hard-coded Google's 8.8.8.8 DNS server, bypassing the Pi-Hole ad blocker.
- remram 3y agoThat's very unkind. It probably took them a good long while to figure out that you did that, in the middle of troubleshooting something else. Why not just block that traffic? People like you are the reason DoH is being rolled out. I hate the concept, but I would immediately enable it if I caught my IT unapologetically getting in the way of my work like you do.
- AviationAtom 3y agoThey seemed to like it less when we blocked it, as their stuff completely failed to work.
- BrandoElFollito 3y agoYes, but at least they immediately knew why.