"Don't Install A DNS Server In My Network!"
- In our first test site, the network administrators immediately said "Don't
install a DNS server in my network!"
- They were probably burnt by DNS servers in the past - it was
non-negotiable.
- If we cannot redirect clients via DNS - we can redirect them via iptables
transparent-proxy rules...
- ...provided that our appliance is "in the middle" (connected as a router),
or the network administrators can add a transparent proxy rule on their
current router.
- A little more coding and GUI changes, and we can select between proxing
via DNS or proxing via iptables.
Originally written by
guy keren