Recursor: NS-IP based Resolution Strategy Under Network Isolation (RPZ / NS-Based Routing) #17143
Unanswered
Heshmatkhah
asked this question in
Q&A
Replies: 2 comments 2 replies
-
|
Helloo . Have no idea bout this kinda stuff but lads pls lend a hand to the WEAKLINGS 🥀😭 -From iran |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
I see no way to do this with Recursor ate the moment. #15808 could be a building block, but as mentioned there there are issues with the PR in it current state. Also, the fallback forward should be of the recursive type, something which the PR does not do at all. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi,
It has now been approximately 48 days since external internet access in Iran has been shutdowned.
A primary technical consequence is DNS fragmentation:
I’ve tested multiple mitigation approaches without success. I’m now evaluating a policy-based routing solution at the DNS layer and need guidance on feasibility and implementation.
Current setup / constraints:
Target behavior:
What I’m looking for:
NSIP/NSDNAMEusable within RPZ or equivalent policy engines.Key challenge:
Resolvers without upstream internet must still be able to delegate “external” domains via a reachable forwarder, while preserving direct resolution for internal/reachable zones.
If anyone has implemented something similar or can suggest a workable design, I’d appreciate concrete guidance.
Beta Was this translation helpful? Give feedback.
All reactions