logoalt Hacker News

toredashtoday at 5:34 AM3 repliesview on HN

Is there any DNS based software to do block/allow? Kinda lika what's present in CiliumNetworkPolicies in Kubernetes networking?


Replies

M95Dtoday at 7:19 AM

Yes, PiHole is the most common, but malware can easily bypass that using shared domains, P2P or IP addresses directly.

Use a filtering proxy instead and no gateway / route to the internet.

Milpoteltoday at 5:52 AM

You mean like PiHole or AdGuard?

gus_today at 7:48 AM

OpenSnitch (+ block lists) ;)

or DNS stubs with filtering capabilities.