5 ms·
When I said blocking all outbound 53 I meant no exceptions, my local forwarder already uses DoH to an outside resolver. Everything that I don't have complete v
by addingnumbers 5y ago
When I said blocking all outbound 53 I meant no exceptions, my local forwarder already uses DoH to an outside resolver.
Everything that I don't have complete visibility into the network stack of goes on a VLAN that does not forward traffic to the internet, it advertises a proxy via WPAD and DHCP option 252. I have a whitelist of hostnames that each device is allowed to make CONNECT requests to, so far there is only one.
If it's not a plain unencrypted HTTP request to my proxy, or a CONNECT request involving a server/device pair I've decided to trust, it's not going anywhere.
This breaks a lot of things that I would just as soon rather do without. I can't change my universal remote hub settings from the vendor portal, boo-hoo. I can't view my cameras from the hardened VLAN or from the internet (unless I VPN in first since the only copy of the recordings is on my local NAS)... good.