Blocked that hard-coded google dns garbage.

  • Silejonu@kbin.social
    link
    fedilink
    arrow-up
    0
    ·
    1 year ago

    I suspect DoT and DoH still go through, though? I mean you can always block the port 853 for DoT, but DoH is another story.

    • jemikwa@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      1 year ago

      Yeah you’d need an L7 application layer filtering firewall to catch DoH since it would detect the SSL packet signature on port 53. Unfortunately that balloons the cost of the device past a reasonable level for a home aficionado.
      A workaround for now would be to block known public servers that use DoH like Google DNS, since a lot of devices are adding features to enable DoH by default at the OS level