[DNSfirewalls] something new in dns firewalls: microsoft dns policy filtering

Francis Turner francis at threatstop.com
Tue May 19 23:58:57 UTC 2015


It seems to only cover the equivalent of QNAME and rpz-client-ip. No equivalent of rpz-ip or rpz-ns* 
But it's a start

Francis J.M. Turner 
VP Research & Security - http://www.threatstop.com/

ThreatSTOP(tm) Inc, "Stop Botnets Stealing from You!" 
email: francis at threatstop.com skype: francis.turner.threatstop
fixed: +1-760-542-1550    cell:  +1-760-402-7676

Newton's Third Law of Experts:
     for every expert there is an equal and opposite expert


> -----Original Message-----
> From: DNSfirewalls [mailto:dnsfirewalls-bounces at lists.redbarn.org] On
> Behalf Of Paul Vixie
> Sent: 19 May 2015 16:53
> To: Rod Rasmussen
> Cc: dnsfirewalls at lists.redbarn.org
> Subject: Re: [DNSfirewalls] something new in dns firewalls: microsoft dns
> policy filtering
> 
> 
> 
> Rod Rasmussen wrote:
> > This is cool.  For us in the TL;DR crew this seems to be a cookbook/example
> approach without tech specs.  Any word on if there is any compatibility with
> RPZ format, or is someone going to have to create a translator?
> 
> i don't see enough overlap that a translator would be possible. and there's no
> RPZ compatibility.
> 
> --
> Paul Vixie
> _______________________________________________
> DNSfirewalls mailing list
> DNSfirewalls at lists.redbarn.org
> http://lists.redbarn.org/mailman/listinfo/dnsfirewalls
> 
> -----
> No virus found in this message.
> Checked by AVG - www.avg.com
> Version: 2015.0.5941 / Virus Database: 4342/9784 - Release Date: 05/15/15


More information about the DNSfirewalls mailing list