Re: Can one construct an IPTables rule to block on NS records?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On 6 October 2015 at 00:46, James B. Byrne <byrnejb@xxxxxxxxxxxxx> wrote:

> So, is there any convenient way to construct an IPTables rule to block
> all IPs associated with a given Domain Name server?
>

​You can use ipsets to block a large collection of IP addresses with
netfilter.  I block various problematic countries that way.

The problem is getting _all_ the IP addresses associated with a DNS
server.  I don't think that is going to be easy/possible, unless that DNS
sever has been badly misconfigured.



​K​
_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
https://lists.centos.org/mailman/listinfo/centos




[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux