LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 04-21-2018, 10:41 PM   #1
mpapet
Member
 
Registered: Nov 2003
Location: Los Angeles
Distribution: debian
Posts: 548

Rep: Reputation: 72
The "Right Way" to Block Domains with Bind9


I am a DNS newbie and have set up Bind9 as an adblocking server inside my LAN.

I've seen adblocking zones written as returning localhost and still others returning NXDOMAIN. I basically have an entry for each ad-serving domain, and then point the domain to an internal IP address.

Is one way more "right" than another?

This might be a dumb question: Is there a better way to handle subdomains? For example, hybl9bazbc35.pflexads.com as a domain entry plfexads.com, then the hyb... part as a host?

Last edited by mpapet; 04-21-2018 at 11:10 PM.
 
Old 04-23-2018, 08:11 AM   #2
MensaWater
LQ Guru
 
Registered: May 2005
Location: Atlanta Georgia USA
Distribution: Redhat (RHEL), CentOS, Fedora, CoreOS, Debian, FreeBSD, HP-UX, Solaris, SCO
Posts: 7,831
Blog Entries: 15

Rep: Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669
I'd say using DNS for this purpose isn't correct.

You should use a firewall instead. Allow the things you want and block everything else.

Security by inclusion of what you know is always better. Trying to exclude the ever changing number of new things on the internet would be an administrative nightmare.
 
Old 04-24-2018, 12:42 PM   #3
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,974

Rep: Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623
Some how to's on web for this. https://charlieharvey.org.uk/page/ad...th_bind_apache

At some point in all this you'll need some list. There are black and white lists that might be used. There are hosts files that could be used too. The list of bad places is pretty large.

Some dns services will help to provide filtering also.
 
  


Reply

Tags
adblock, bind, dns



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
"/Users/Shared/H&R Block" on an OS/X system?! "Hell, no!" But ... sundialsvcs Linux - Security 1 02-14-2015 04:13 AM
Redirect "/roundcube" to "webmail." for all virtual domains? snowweb Linux - Server 2 08-13-2012 08:58 AM
Bind9 : No text file "A record" but it can be resolved" iniwidi *BSD 3 08-15-2011 03:12 AM
"dig mx" and "ping google" do not work when bind9 runs.. why? alexxxis Linux - Software 4 01-07-2007 03:16 AM
"dig mx" or "ping" not working because of bind9? alexxxis Debian 4 01-06-2007 11:26 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 09:44 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration