Re: DNS Queries Using API - BIND9

2020-05-11 Thread Blason R
Hmmm nice suggestion and appreciate that. But it would too much for normal user looking for more simpler manner. Any way if no option then will have to live with vpn option for now. On Mon, 11 May 2020, 22:34 Petr Menšík, wrote: > Hi, > > AFAIK BIND is supported also on Windows. Would it be

Re: DNS Queries Using API - BIND9

2020-05-11 Thread Petr Menšík
Hi, AFAIK BIND is supported also on Windows. Would it be possible just to install BIND service on local machine and configure it to download DLZ zone from your servers. It could authenticate using ddns keys. And forward would be also straightforward. As a bonus, they would get local validating

Re: DNS Queries Using API - BIND9

2020-05-11 Thread Reindl Harald
Am 11.05.20 um 06:14 schrieb Blason R: > I am seeking solution for our below problem and wanted to know if any > open source option can help us here? > We have our internal DNS RPZ firewall built on BIND9. Due to the current > situation since all users are working from home we are not able to

Re: DNS Queries Using API - BIND9

2020-05-11 Thread Blason R
Nah those are regular users - And thinking to work on DoT Proxy and force that through GPO for browsers. On Mon, May 11, 2020 at 12:27 PM Vadim Pavlov wrote: > If your users has admins permissions you probably will not find any open > source tool which support that. For restricted accounts on

Re: DNS Queries Using API - BIND9

2020-05-11 Thread Vadim Pavlov via bind-users
If your users has admins permissions you probably will not find any open source tool which support that. For restricted accounts on Win - create policies. BR, Vadim > On May 10, 2020, at 23:52, Blason R wrote: > > Thats a nice starting point - > >

Re: DNS Queries Using API - BIND9

2020-05-11 Thread Blason R
Thats a nice starting point - https://www.nginx.com/blog/using-nginx-as-dot-doh-gateway/ But still looking for any client utility so that users can not shutdown or can not suspend the service On Mon, May 11, 2020 at 12:18 PM Blason R wrote: > Hmm- Any docs on configuring DOH Proxy? > > On

Re: DNS Queries Using API - BIND9

2020-05-11 Thread Blason R
Hmm- Any docs on configuring DOH Proxy? On Mon, May 11, 2020 at 11:56 AM Daniel Stirnimann < daniel.stirnim...@switch.ch> wrote: > > > On 11.05.20 08:18, Vadim Pavlov via bind-users wrote: > > The main issue that bind does’t provide an authentication method. So in > > any case you somehow should

Re: DNS Queries Using API - BIND9

2020-05-11 Thread Blason R
I can do that - But 1. How can I control unauthorized use? 2. Since one its populated over Internet it can be used by any one right? 3. Plus from user end they can change the DNS to avoid protection. On Mon, May 11, 2020 at 11:01 AM Reindl Harald wrote: > > > Am 11.05.20 um 06:14

Re: DNS Queries Using API - BIND9

2020-05-11 Thread Vadim Pavlov via bind-users
Good idea. It may work. I’m using Intra for 1.5 years (with my DNS) and actually didn’t try it likely my DoH “old” proxy probably doesn’t support it. With nginx it should be possible if these open source clients support it. For Win/Mac/Linux there should be some open source DoH clients (backup

Re: DNS Queries Using API - BIND9

2020-05-11 Thread Daniel Stirnimann
On 11.05.20 08:18, Vadim Pavlov via bind-users wrote: > The main issue that bind does’t provide an authentication method. So in > any case you somehow should manage the access to the DNS server vice > versa it will became open resolver and will be used for DDoS attacks. If you were to use DoH,

Re: DNS Queries Using API - BIND9

2020-05-11 Thread Vadim Pavlov via bind-users
Hi Blason, There are open source clients for iOS (DNSCloak) and Android (Intra) which use DoH (you will need to install a DoH proxy) but I’m not aware about free clients for Mac/Windows/Linux (may be because they have embedded clients which can be configured to use any 3rd party DNS :). The