Hacker News new | past | comments | ask | show | jobs | submit login

This and I combo it with restricting DNS lookups to the actual LAN servers. No way to bypass the DNS at that point via the firewall.



> This and I combo it with restricting DNS lookups to the actual LAN servers.

This won't prevent OPs concern with apps doing DNS over HTTPS, would it?

> No way to bypass the DNS at that point via the firewall.

Some apps do not even do DNS and connect to static IPv4s and IPv6s straight-away. Even if IPv4 is limited, plenty IPv6 to go around than an ip-table can handle.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: