I have read the following story about VPN tunnelling over port 53 at
a mobile carrier but that is related to routing and I would trust
that unbound is not the tool/place to control/analyse routing or be
in charge of network traffic/package payload control, though bind
features > rate-limit { responses-per-second ; } <
On 22.11.2018 15:07, via Unbound-users wrote: I happened to hear from some DNS operators at some mobile carriers the other day who are scratching their heads about DNS tunnelling; they zero-rate DNS traffic for a variety of sensible reasons, but some of their more cunning customers have noticed that if they stop caring so much about performance, zero-rating DNS traffic can be turned into zero-rated mobile data.It sounds like outlier identification (to find the unusually talkative mobile terminals) and rate-limiting (to make tunnelling painful without stamping too hard on DNS resolution) are the tools people have to work with. It might be nice if there were some convenient recipes for tuning unbound to do that kind of thing (from the perspective of the DNS operator/carrier, I guess, not the mobile terminal user).Joe |
- IN TXT & NULL trash records Maciej Gawron via Unbound-users
- Re: IN TXT & NULL trash recor... ѽ҉ᶬḳ℠ via Unbound-users
- Re: IN TXT & NULL trash r... A. Schulze via Unbound-users
- Re: IN TXT & NULL tra... ѽ҉ᶬḳ℠ via Unbound-users
- Re: IN TXT & NULL tra... Joe Abley via Unbound-users
- Re: IN TXT & NULL... ѽ҉ᶬḳ℠ via Unbound-users
- Re: IN TXT &... Joe Abley via Unbound-users
- Re: IN TXT &... ѽ҉ᶬḳ℠ via Unbound-users
- Re: IN T... ѽ҉ᶬḳ℠ via Unbound-users
- Re: IN T... Maciej Gawron via Unbound-users
- Re: IN T... Paul Vixie via Unbound-users
- Re: IN T... Maciej Gawron via Unbound-users
- Re: IN T... ѽ҉ᶬḳ℠ via Unbound-users
- Re: IN T... Paul Vixie via Unbound-users
- Re: IN T... ѽ҉ᶬḳ℠ via Unbound-users
- Re: IN T... Wouter Wijngaards via Unbound-users
