Page MenuHomeVyOS Platform

RPZ support in DNS forwarder for DNS Firewall
Open, NormalPublicFEATURE REQUEST

Description

Hello,
to provide DNS firewall capabilities we will need to add RPZ support to the DNS forwarder
https://doc.powerdns.com/recursor/lua-config/rpz.html

Details

Version
-
Is it a breaking change?
Perfectly compatible
Issue type
Feature (new functionality)

Event Timeline

syncer assigned this task to hagbard.
syncer triaged this task as Normal priority.
hagbard subscribed.
erkin set Issue type to Feature (new functionality).Aug 31 2021, 5:19 PM

Response Policy Zone (RPZ)
It would be very very useful feature in VYOS
RPZ allows admins to easily block access to websites via DNS lookup. The lookup is done before the main communication which is based on IP addresses ( which can be blocked by IP Address Blocklists ). Usually the URLs of malicious websites do change much less often, compared to the IPs of them.

Response Policy Zone (RPZ) is a mechanism to define local policies in a standardized way and load those policies from external sources. This is done usually by application like PiHole ( running on device in the local network ). This addon allows this functionality as part of Powerdns
RPZ is a straightforward way to stop users from connecting to harmful sites like phishing pages or malware servers while keeping the network and its users safe with minimal fuss.

An easy to use allowlist is handy for avoiding issues when legitimate sites get flagged by mistake or need to stay accessible for business reasons.