whitelist

Leandro Roggerone leandro at tecnetmza.com.ar
Tue Jan 19 12:20:42 UTC 2021


El mar, 19 ene 2021 a las 9:19, Leandro Roggerone (<leandro at tecnetmza.com.ar>)
escribió:

> Dear Paul , I'm new on the list and have not much experience with dns
> practices.
> Can you explain why the word "blacklist" makes you feel bad ?
> I'm trying to avoid my users to get access to malware sites and so ...
> So far, my setting is working good, I can see it working at my librenms
> stats.
> [image: dns_blacklist.png]
> I received  just a few customer complaints about some legitim sites they
> could not access.
> That's why I would like to add them to a whitelist.
> After reading your link it is not clear for me how to create this
> whitelist.
> In order to block malicious sites , i'm doing this:
>
> local-zone: "zzz.aba.vg" always_nxdomain
> local-zone: "zzz.clickbank.net" always_nxdomain
> local-zone: "zzz.onion.pet" always_nxdomain
>
> What should I do , to allow those entries with higher precedence than
> blacklist.
>
> BTW ; if you know a better way to achieve the same , please share with us
> !!
> Thanks.
>
> El dom, 17 ene 2021 a las 17:48, Paul Vixie (<paul at redbarn.org>) escribió:
>
>>
>>
>> Leandro Roggerone via Unbound-users wrote on 2021-01-14 06:30:
>> > Hi guys.
>> > Im trying to find without success how to create a whitelist to bypass
>> > false positive domains listed on my blocklist.
>> >
>> > So far ... what I do is to remove false positives from blocklist.
>> > This is not so effective since , I will need to do everytime I update my
>> > lists.
>>
>> this is probably the last time i will answer a question that contains
>> the word "blocklist". (i'm sure that comes as a relief to many!)
>>
>> >
>> > Do you know how to implement whitelist ?
>>
>> https://tools.ietf.org/id/draft-vixie-dnsop-dns-rpz-00.html#rfc.section.3.3
>>
>> --
>> Sent from Postbox
>> <
>> https://www.postbox-inc.com/?utm_source=email&utm_medium=siglink&utm_campaign=reach
>> >
>>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.nlnetlabs.nl/pipermail/unbound-users/attachments/20210119/37cd6259/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: dns_blacklist.png
Type: image/png
Size: 120161 bytes
Desc: not available
URL: <http://lists.nlnetlabs.nl/pipermail/unbound-users/attachments/20210119/37cd6259/attachment-0001.png>


More information about the Unbound-users mailing list