5
you are viewing a single comment's thread
view the rest of the comments
[-] swizzlestick@lemmy.zip 1 points 3 weeks ago

Sometimes even that's not enough. I've had some questionable kit before that would just ignore the DNS settings fed to it if it thought they were no good, and fall back to something else preconfigured.

pfSense is a wonderful tool for situations like that. Anything intended for local use only here just doesn't get outside at all. Handy for stuff like a fire stick that only needs to be calling up a local media library.

It can also mangle any DNS requests going out to a different server and redirect them to itself instead. You could do this without it with iptables/nftables on a generic Linux box, but pfSense makes it much friendlier.

There are other packages that can do the same, but physically all you need is one piece of hardware as a bouncer that manages connections between inside/outside.

this post was submitted on 16 Apr 2025
5 points (100.0% liked)

Technology

69869 readers
2437 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS