Skip to content

Can I enforce cloaking rules only for certain clients? #2424

Answered by o101010
crichez asked this question in Q&A
Discussion options

You must be logged in to vote

Hi,

Just some ideas that could help you.

  • You can reduce the DNS TTL for those records. I don't think DNSCrypt-proxy is able to do that. You can setup a forward server to a "real" local DNS server.

  • On Palo Alto NGFW, we have something called Policy Based Forwarding (or PBF). Those rules are applied before reading of route table and can redirect a request to another host or interface depending on source and destination ip and application. Maybe you can try to find something like that on your router. So, you don't need cloaking any more.

EDIT : You can setup a TTL for cloacking in your configuration file

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@crichez
Comment options

Answer selected by crichez
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants