[afnog] ICMP/DNS tunneling mitigation

Stephane Bortzmeyer bortzmeyer at nic.fr
Tue Dec 20 10:32:33 UTC 2011


On Tue, Dec 20, 2011 at 02:03:12AM -0800,
 SM <sm at resistor.net> wrote 
 a message of 8 lines which said:

> >Won't work (think about how DNS works).
> 
> Some form of DNS will still work.  

I did not say "DNS won't work", I said "your solution won't block
IP-over-DNS". Hint: DNS works by relaying.



More information about the afnog mailing list