/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ > Keep in mind kernals do not know hostnames. In fact, > they do not even know dotted quads. They know an IP > address by a four byte register. I know that :) I shouldn't have brought kernels into the issue. After the post I realized (to late) that it is idiot to filter hostnames in kernel, since the packets arrive there as numerals identifying IPs. > If you block me from going to www.playboy.com what > stops me from typing http://208.251.29.10 instead. > If I find someone who had an authoritative bind > server I can even make whatever domain name I wish > be 208.251.29.10. So filtering by IP makes perfect > sense. You're absolutly right. I just want to avoid the DNS lookup from bringing my connection up, since there will be no usefull traffic except the DNS query itself. > It would make more sense to put comments in your masq > script denoting who each IP address belongs to and > why it is being blocked. In the specific case of > a web address, a proxy server, which will result in > an error page, would make more sense then simply not > loading the page, as would ipmasq. In the latter the > user could assume many things, mostly network related, > and never guess he was simply being blocked. If I setup a proxy server (thus having to deny everything comming from the LAN to port 80) will the proxy server bring a DNS lookup for a hostname (I am assuming I can deny hosts to the proxy by hostname, don't recall right now) > With a bind server you could redirect those queries > to a specifc ip address. I do not think this is what > you had in mind however as you would be creating > gigantic zone files simply for the fact you want to > fake a certain nslookup. So for http traffic the problem would be solved. And what about a "telnet xpto.com nnn"? It would still bring the line up... What I need is something that captures the action comming from the kernel, and if it is a DNS query, simply ignore it... How would you protect your office LAN from phone bills, then? Thanks again, Raul _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
