/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Raul Carvalho wrote:

> 
> > ipchains can't do this but if you go to
> > http://www.zip.com.au/~raf2/lib/software/firewall
> > and download the latest version, you'll find a
> > utility called dns2ip which reads stdin, replacing
> > all domain names with their corresponding ip address(es).
> 
>  I've seen this, but this is not what I need. dns2ip makes DNS queries,
> thus activating the line...

yes, but it outputs ip addresses. you don't run it at boot time.
you run it at regular intervals when you're already connected.
then, at boot time, you have a firewall script that only contains
(fairly up to date) ip addresses, and doesn't require any dns queries.

>  any more ideas? It seems very *unusefull* to the dial on demand user a
> piece of software that do not filter by host name..
> 
>  There should be a way of filtering by hostname first in the kernel
> (without knowing the IP). If someone filters by name, th IP shouldn't be
> necessary at all..
> 
>  If I load netscape and goto www.playboy.com I want this address to be
> bloked, thus iot makes no sense knowing it's IP to filter it by IP!! Why
> not by hostname? Why not both?

this is not possible. the packets do not contain hostnames.
they contain ip addresses. if the kernel were able to cope
with this it would mean that the kernel would have to perform
dns lookups itself which would result in a huge network
performance hit and it still wouldn't avoid unwanted dialouts.

>   Can I filter DNS queries of a specified hostname?

set up a dns server for internal use that acts as the authoritative
name server for any domains that you want to block. then, this dns
server, under your control, can define whatever ip addresses you like
(including none). then, you always know what the ip addresses are because
you define them yourself. this keeps working whenever the real domain
changes its ip addresses (cf doubleclick.net).

alternativaly (easier), get junkbusters. it will filter http reuests
by domain name. it sounds like that is all you require.

raf

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to