Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 | 3 
muppet
2644 posts

Uber Geek
+1 received by user: 1662

Trusted

  #2026062 31-May-2018 07:51
Send private message

The problem is going to be though, how can you control what DNS server is used for each service?

 

I guess if you use Unbound in full recursion mode and ensure you route the authoritive nameservers for each service out the appropriate VPN you might get this to work.  But otherwise Netflix USA are going to see DNS requests coming from a NZ IP address etc.

 

 




Brend

97 posts

Master Geek
+1 received by user: 21


  #2026080 31-May-2018 09:02
Send private message

Isn't it possible to have a static diversion route that will divert all URLs in http://asn.blawk.net/9901 for Neontv? Hmmm ... I guess that is the same the firewall rules are trying to accomplish...

 

Can one assign different "sets" of DNS to different gateways? 

 

I did contact NeonTV to tell them about this issue. They will look into it... or so they said





I am the reason idiot's guides exist


muppet
2644 posts

Uber Geek
+1 received by user: 1662

Trusted

  #2026145 31-May-2018 11:48
Send private message

No, you can't assign different DNS to different gateways.  The DNS server used is something the client picks.

 

You can use the Unbound DNS server in pfSense to "walk the DNS tree" instead of acting your local ISPs nameserver (or google's etc).  This is slower, but it would allow you to route your requests for DNS out various gateways.  When you lookup .com you get told talk to netflix.com and when you go to talk to netflix.com's nameservers, you'd have a route in the table for their namservers that goes out your VPN-US server.  Probably covered by the routing you already have in place for their netblocks.

 

But yes, this is where it'll get tricky.  You can't just send all your requests to your ISP, or to an overseas server, unless it is doing some clever lookup stuf for you already (maybe some of them do)


1 | 2 | 3 
View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.