LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-07-2011, 06:17 PM   #1
Ulysses_
Senior Member
 
Registered: Jul 2009
Posts: 1,303

Rep: Reputation: 57
Domain name whitelisting


Is it possible to do the equivalent of a domain-name allow rule using a firewall plus a DNS server working together as follows?

A script keeps reading the DNS logs. Every time the script sees a successful DNS lookup, it generates a firewall allow rule for the associated IP. All other IP's the firewall blocks by default. The DNS server is configured to only allow look-ups to a whitelist of domain names.

So no other IP can be accessed, only what the DNS server returns when the domain name is in the whitelist.

Will this work, is it possible?
 
Old 08-08-2011, 04:19 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Erm... why?? As nice an idea as it might seem to you, don't. I can't imagine this could ever leave you in a happy place. If you already have a whitelist, why not just convert that into rule directly? What kind of rules are you adding? Per source IP? that would get really out of hand quickly. There will be a better way to achieve your original goal, I'm sure. Like a decent web proxy.

Last edited by acid_kewpie; 08-08-2011 at 04:21 AM.
 
Old 08-08-2011, 09:12 AM   #3
Ulysses_
Senior Member
 
Registered: Jul 2009
Posts: 1,303

Original Poster
Rep: Reputation: 57
Quote:
Originally Posted by acid_kewpie View Post
Erm... why?? As nice an idea as it might seem to you, don't.
Because the other way to whitelist domains, using squid or other proxies, would need too much memory so the VM it would run on would not leave space for the other 3 or 4 VM's that are required at the same time.

Quote:
If you already have a whitelist, why not just convert that into rule directly?
I do not yet, but the firewall rules would be per-destination IP (this is for parental control initially, more uses to follow). Where the IP's are known in advance to be associated with youtube.com, yahoo.com and anotherdomain.com, say.

But youtube.com does not have just one IP. Even the list of IP's it has is variable. So domain-name rules are required instead. Firewalls cannot do such rules, so why not dynamically give them the per-IP rules they need, in response to DNS server lookups? There are even floppy linuxes that can run a firewall and a DNS server on 24 MB of ram.

Last edited by Ulysses_; 08-08-2011 at 09:14 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Email - unapproved Whitelisting loftus49 Fedora 4 06-10-2010 10:25 PM
Whitelisting specific domain for rDNS green_dood Linux - Networking 1 02-22-2010 02:17 AM
WhiteListing My Mail Domain fedoraman Linux - Server 1 05-19-2008 05:55 AM
Whitelisting websites in linux OneSeventeen Linux - Networking 1 12-08-2005 11:29 AM
postfix question - whitelisting wijnands Linux - Software 2 03-30-2005 03:28 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration