Page 1 of 1

Blocking WAN DNS resolving

Posted: Tue Dec 13, 2016 11:57 am
by Andrue
Hi,

I'm upgrading from a 6300 to an 8800nl r2. With the 6300 I had to redirect port 53 to a non-existent LAN address in order to disable public DNS resolving. Is this still an issue with the 8800? The manual claims it as a feature (although why it should class it as a good thing I don't know). There's also this page from AAISP that applies to a different model of Billion.

It looks like I can do something similar with the 8800 but the page looks slightly different.

I emailed Billion support and got this slightly cryptic response:

"Is the firewall enabled for the WAN connection?? (Configuration >> WAN >> WAN Service, edit your WAN connection and see if the firewall option is ticked/enabled)"

Re: Shutting down the DNS relay

Posted: Tue Dec 13, 2016 12:06 pm
by billion_fan
Andrue wrote:Hi,

I'm upgrading from a 6300 to an 8800nl r2. With the 6300 I had to redirect port 53 to a non-existent LAN address in order to disable the public DNS relay. Is this still an issue with the 8800? The manual claims it as a feature (although why it should class it as a good thing I don't know). There's also this page from AAISP that applies to a different model of Billion.

It looks like I can do something similar with the 8800 but the page looks slightly different.

I emailed Billion support and got this slightly cryptic response:

"Is the firewall enabled for the WAN connection?? (Configuration >> WAN >> WAN Service, edit your WAN connection and see if the firewall option is ticked/enabled)"
The 8800 is different to the 6300 series.

As long as the firewall is enabled on the WAN side your router should not respond to recursive DNS requests (if your firewall is not enabled your router will respond to recursive DNS requests, hence why we were asking if the firewall was enabled or not)

You can always test this using the following link to be sure :D

http://openresolver.com/?ip=

Re: Blocking WAN DNS resolving

Posted: Tue Dec 13, 2016 1:54 pm
by Andrue
Ah, great, thanks. Yes, the firewall will be on.