4 ms·
It's really not. There's different ways one can do this, but it's not hard down to lock down outbound traffic. On a more general note, tangential to the articl
by DistractionRect 3y ago
It's really not. There's different ways one can do this, but it's not hard down to lock down outbound traffic.
On a more general note, tangential to the article and specifically regarding blocking DoH and friends, it's pretty trivial to do this with a DNS backed firewall. I do this for my IoT vlan:
- default deny all outbound
- set dnsmasq to populate an ipset/nftset with DNS responses
- have a firewall rule that hole punches for traffic destined for any ip in the set
- now it's just DNS filtering like usual
This means any successful outbound connection must be prefixed with a successful DNS query that is resolved by the local Dnsmasq instance. Any query that hits an unblocked DNS endpoint does not populate the set used for whitelisting, and is dead in the water - making DoH, DoT, DoQUIC, and such unviable.
Obviously, hole punch exceptions as needed (E.g. For direct connects to static ip addresses).
- kkielhofner 3y agoOnce you authorize any domain that resolves to Cloudflare POP IPs you’re going to end up with gigantic holes that essentially neuter this approach. It may work in the limited context that is your IoT network but for any corp, user of the web, etc Cloudflare IPs will open almost immediately for all but the most selective (non-CF) DNS records. Or you don’t allow any CF DNS records or IP ranges and cut yourself off from half the internet. That’s what parent meant.
- _8j50 3y agoYour suggestions don't work well at scale and when restricted to specific firewalls and other infra, especially at large orgs.