Is Firewalla using an RPZ Feed (DNS Sinkhole) ?

Comments

5 comments

  • Avatar
    Firewalla

    Firewalla has a DNS forwarder that can filter DNS queries. (Data plane block is also there on the traffic side).

    What is the RPZ feed you are talking about? it can be many different things. (applicable or not to a DNS forwarder, we need to look)

    0
    Comment actions Permalink
  • Avatar
    Chris Thomas

    Also known as "DNS Firewall" .. A response policy zone (RPZ) is a mechanism to introduce a customized policy in Domain Name System servers, so that recursive resolvers return possibly modified results. By modifying a result, access to the corresponding host can be blocked.

    https://en.wikipedia.org/wiki/DNS_sinkhole
    https://en.wikipedia.org/wiki/Response_policy_zone
    https://dnsrpz.info/

     

    Example of use

    Consider that Alice uses a computer which uses a DNS service (recursive resolver) which is configured to use RPZ and has access to some source of zone data which lists domains that are believed to be dangerous.

    Alice receives an email with a link that appears to resolve to some place that she trusts, and she wishes to click on the link. She does so, but the actual location is not the trusted source that she read but a dangerous location which is known to the DNS service.

    As the DNS service realizes that the resulting web location is dangerous, instead of informing her computer how to get to it (unmodified response), it sends information which leads to a safe location. Depending on how the DNS service configures its policy actions, the modified response can be a fixed page on a web site which informs her of what has happened, or a DNS error code such as NXDOMAIN or NODATA, or send no response at all.

     

    ...ct

     

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    DNS filtering is already there. You can also add your own using the "rules" system. You can define your own by using the rules system.  See https://help.firewalla.com/hc/en-us/articles/360008521833-Manage-Rules

    In this document look for domain block mode

    • default: block domain via DNS, and block IP
    • domain: block domain via DNS

     

    0
    Comment actions Permalink
  • Avatar
    Chris Thomas

    Yes, I know I can block an individual domain.

    I'm talking about subscribing to an RPZ feed, so that Firewalla would automatically block access to all of the domains in the feed.

    0
    Comment actions Permalink
  • Avatar
    Chris Thomas

    Basically what Pi-Hole does.

    0
    Comment actions Permalink

Please sign in to leave a comment.