/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


> Keep in mind kernals do not know hostnames.  In fact,
> they do not even know dotted quads.  They know an IP
> address by a four byte register.

 I know that :) I shouldn't have brought kernels into the issue.
After the post I realized (to late) that it is idiot to filter
hostnames in kernel, since the packets arrive there as numerals
identifying IPs.

> If you block me from going to www.playboy.com what
> stops me from typing http://208.251.29.10 instead.
> If I find someone who had an authoritative bind
> server I can even make whatever domain name I wish
> be 208.251.29.10.  So filtering by IP makes perfect
> sense.

 You're absolutly right. I just want to avoid the DNS
lookup from bringing my connection up, since there will
be no usefull traffic except the DNS query itself.

> It would make more sense to put comments in your masq
> script denoting who each IP address belongs to and
> why it is being blocked.  In the specific case of
> a web address, a proxy server, which will result in
> an error page, would make more sense then simply not
> loading the page, as would ipmasq.  In the latter the
> user could assume many things, mostly network related,
> and never guess he was simply being blocked.

 If I setup a proxy server (thus having to deny everything
comming from the LAN to port 80) will the proxy server bring
a DNS lookup for a hostname (I am assuming I can deny hosts
to the proxy by hostname, don't recall right now)

> With a bind server you could redirect those queries
> to a specifc ip address.  I do not think this is what
> you had in mind however as you would be creating
> gigantic zone files simply for the fact you want to
> fake a certain nslookup.

 So for http traffic the problem would be solved. And
what about a "telnet xpto.com nnn"? It would still bring
the line up...

 What I need is something that captures the action comming
from the kernel, and if it is a DNS query, simply ignore it...

 How would you protect your office LAN from phone bills, then?

 Thanks again,
 Raul

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to