Page 1 of 1

REQUEST: Names instead of IP (allowed / disallowed)

Posted: 2017-10-25 20:37
by M*I*B
Hello there from germany,

is there a change in the near future to use names (DDNS, MyFritz, ...) instead of IP- adresses for i.e. IP-Filter?!?

Re: REQUEST: Names instead of IP (allowed / disallowed)

Posted: 2017-10-25 22:41
by botg
No, reverse DNS is too unreliable.

Re: REQUEST: Names instead of IP (allowed / disallowed)

Posted: 2017-10-31 09:58
by M*I*B
In what way? Regarding name resolution or security?

Regardless, DDNS is the only way to exclude access for everyone else when you enter the NET with changing IP's.

At the moment, the only and dangerous option is to open the server for all addresses, at minimum for all ranges of your DSL-providers IP pool. If you do not know what your next IP address will be or what IP pool will come from, you might still have to access it on the go, opening a wide range like a barn door is the only viable option.


The question remains, what is better now: An open barn door or an occasionally not working name resolution?!?

I think the answer is simple ... is'nt it?!

Re: REQUEST: Names instead of IP (allowed / disallowed)

Posted: 2017-10-31 10:14
by botg
For controlling access all you need to a long password.



With RDNS, everybody could claim the IP address belongs to a certain domain name. What you need is a forward-confirmed reverse DNS lookup, to make sure the hostname in turn maps back to the IP address in question.

Not only is this a quite slow operation, it can also fail. What should be done if the lookup fails?

Last but not least it can be mis-used for reflection attacks and possibly amplification attacks. Bad guy connecting to your server with an intentionally wrong PTR record associated with the attackers IP and your server (or your DNS resolver) then does requests to the actual target IP on the forward part of the resolution.