EFW Support

Support => EFW SMTP, HTTP, SIP, FTP Proxy Support => Topic started by: Skeesicks on Thursday 03 March 2011, 04:16:49 am



Title: DNS Proxy and Anti-Spyware
Post by: Skeesicks on Thursday 03 March 2011, 04:16:49 am
Hi,

I am running Endian 2.4.1 and want to use the DNS Proxy with activated Anti Spyware but this does not work.
If I access a domain listed in the malwaredomains file or if I create manual blacklist entries, they are not blocked.

This is no dns cache issue, because I tried directly with nslookup and no dns answer is redirected.

I looked in /etc/dnsmasq and I saw a reference for  blackholedns.conf in dnsmasq.conf but  blackholedns.conf is empty.

If I disable the DNS Antispyware feature the entry for blackholedns.conf is removed from dnsmasq.conf, so I think the blackholedns.conf file is not updates successfully
but I have no clue, why!

I saw that there is a blackholedns.conf.tmpl, but some lines are commented out and some of the variables not set.

Has anybody been successfull enabling the DNS Antispyware feature on 2.4.1 or am I hitting a bug?


Thanks in advance.

regards,

Matthias


Title: Re: DNS Proxy and Anti-Spyware
Post by: Skeesicks on Friday 04 March 2011, 01:40:48 am
Hi,

I think my problem has solved itself.

After running long enough (this is just a testinstallation, so it runs only frequently) the anti-malware is running.

I think the malwaredomains file was not donwloaded fully, because now there are entries in blackholedns.conf.

So all you have to do, if you encounter the same problem, is to wait for the list to download.