- CheckMates
- :
- Products
- :
- General Topics
- :
- DNS rewriting Hack
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DNS rewriting Hack
I have found an interesting way to rewrite DNS requests to other IP addresses.
This makes it possible to use the internal private addresses on the internal DNS server for the DNS requests.
External DNS queries that are requested via the Internet can be rewritten to official addresses on the firewall.
The ISP function can be used as a hack for this purpose.
If you activate and configure ISP Redundancy on the gateway, you have the option of rewriting DNS queries. This can be used to rewrite regular DNS queries to other IP addresses.
Example configuration:
1) Enable ISP on the gateway
2) Now select the “Primary/Backup” redundancy mode (see picture 1)
3) Now create an ISP link (that corresponds to your external interface in the direction to the Internet in my example “external_interface”.
4) Unfortunately, two interfaces must be defined, so you have to work with a placeholder interface for ISP2 link. Then create a link that only functions as a placeholder in my example “not_used”. Fictitious IP addresses can be used for the interface.
5) Now enabling “DNS Proxy”
6) In the next step, you can enter the DNS settings that you want to rewrite (red).
You can enter any address for the second ISP backup link (blue), as this is not used in my example.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
not sure if you could call it a "hack" ... it just the way it works i would say ...
overwrite everything with your manual configuration
maybe a dirty way to make split DNS when connecting via Client VPN. 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Thomas_Eichelbu,
Hack or no hack.
Had used ISP in a customer project to do this.
It is the only way I know of to rewrite DNS requests on a gateway😊.
It is a pity that there is no DNS proxy that can be used to rewrite DNS queries. It was a feature request of me years ago.
ISP primary is not designed to rewrite DNS requests, but it can be used to do so, even if only one internet service provider is used.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good point @HeikoAnkenbrand
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Someone must have heard you (and others) as it's integrated into R82: https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Gaia_AdminGuide/Content/Topics-GAG...
The funny thing is that dnsmasq has been installed on Gaia since at least R77.20 though it was disabled.
