LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 01-13-2006, 04:29 PM   #1
uselpa
Senior Member
 
Registered: Oct 2004
Location: Luxemburg
Distribution: Slackware, OS X
Posts: 1,507

Rep: Reputation: 47
DNS proxy w/filtering


Hello,

I am looking for a DNS proxy that allows me to filter which DNS requests are answered and which ones are dropped.

The software should allow me to specify something like this:
192.168.1.5 "www.yahoo.com","www.google.com"
192.168.1.6 "www.google.com"

meaning that the first machine is allowed to resolve the specified 2 names, and the second only "www.google.com".

I have looked at the bind documentation and although I found the view concept, this does not appear to allow me to specify a list of allowed names.

Does anybody know of such a software?
 
Old 01-13-2006, 04:59 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
i don't understand the application here... if you're that strict why use external DNS servers at all? just provide your own dns directly for those sites.
 
Old 01-14-2006, 04:41 AM   #3
uselpa
Senior Member
 
Registered: Oct 2004
Location: Luxemburg
Distribution: Slackware, OS X
Posts: 1,507

Original Poster
Rep: Reputation: 47
The application is as follows:
- In the production network we have a set of Windows, AIX and mainframe DNSes which work fine but are weakly secured. Each DNS manages a different domain.
- In our DMZ we don't have name resolution but we need to implement it. In order to avoid redundancy, we want to implement a proxy DNS. It will also be located in the production network (behind a firewall) but will only be used for requests coming from the DMZ and will forward the request to the correct DNS if it is authorized.
- Machines in DMZ should only be allowed to make name resolution if explicitely authorized by the "ACL" which I described in my first post. Thus is a machine was taken control of, it would be impossible to map out the internal network through the DNS as only the names needed for the applications running on that specific machine would be available.

Is that clearer?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
web filtering thorugh a proxy jsmarshall85 General 4 12-16-2004 10:07 AM
Need advice for internet sharing proxy that supports filtering peterbrowne Linux - Networking 1 11-12-2004 05:27 PM
Safesquid-Content Filtering Proxy Server davidwalton Linux - Software 1 10-15-2004 05:27 AM
Spam filtering usin proxy server. myutopia Linux - General 0 01-14-2004 01:38 PM
SMTP proxy for spam filtering todesengel Linux - Software 2 09-10-2003 11:05 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 08:47 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration