|
|
|
|
|
by assassinator42
992 days ago
|
|
This is going to make it even more of a pain to do egress filtering on networks/systems we administer.
I want to be able to allow list sites with dynamic IPs. The existing solutions for doing this by examining SNI are already often bypassable by forging the SNI (looking at you, AWS Network Firewall). |
|
The second way is to return a “no error no answer” or an NXDOMAIN response to queries made to the use-application-dns.net.
I personally already use the second option to block DoH and cell phones seem to automatically figure out to use port 853 for DNS-Over-TLS on my home router Unbound DNS. I also null route most of the public DoH servers. People point out that DoH can be on any CDN IP but it never has been.
[1] - https://developers.cloudflare.com/ssl/edge-certificates/ech/
[2] - https://learn.microsoft.com/en-us/windows-server/networking/...
[3] - https://github.com/mimuret/iptables-ext-dns