Project

General

Profile

Actions

Feature #4400

closed

allow aliases to enter *.domain.com to block all subdomains

Added by Bipin Chandra about 9 years ago. Updated about 9 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
02/10/2015
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:

Description

it would be better if aliases allowed to enter a * before domain in order to block all different subdomain ips for a single domain, would be very effective for filtering traffic to certain sites and their services which cant be filtered by squid in transparent mode and https.

second option would be to allow regex entries but i know that would be a little tough considering the firewall table needs ip addresses to filter.

Actions #1

Updated by Jim Pingle about 9 years ago

  • Status changed from New to Rejected

That is not possible. Entries must be resolved accurately to have their addresses placed into a table. There is no way, short of sniffing/capturing/proxying DNS, to detect "*.domain.tld", and that is not currently possible nor compatible with the alias mechanisms.

Relying on reverse DNS resolution would be very slow and highly inaccurate for the purpose as well.

Actions #2

Updated by Bipin Chandra about 9 years ago

well one way possible would be to set domain overrides in dns resolver but the problem there is the override applies to all LAN clients, probably some way to apply those overrides per client would be better if thats even possible

Actions

Also available in: Atom PDF