DNS query resolved IPs only for some clients
Posted: Sat Jul 30, 2022 11:18 pm
Hello everyone
So I have some clients in my network that they use VPNs like Psiphon which connect over ports like 443 and 80 which I cannot block and also their like of servers are a lot so I cannot monitor and block the server IPs one by one. So I was wondering if there is a way to block all the IPs for those clients except the ones resolved from DNS server (my router is the internal DNS server for the clients) so in this way client send a DNS query request for mikrotik.com and the answer is IP 449.459.459.555 and they can communicate with this IP cause it was came from a DNS query request reply but if the same client want to communicate with IP 567.564.510.945 they can't because it wasn't a DNS query request reply.
Is it possible ?
Thank you very much for any help
So I have some clients in my network that they use VPNs like Psiphon which connect over ports like 443 and 80 which I cannot block and also their like of servers are a lot so I cannot monitor and block the server IPs one by one. So I was wondering if there is a way to block all the IPs for those clients except the ones resolved from DNS server (my router is the internal DNS server for the clients) so in this way client send a DNS query request for mikrotik.com and the answer is IP 449.459.459.555 and they can communicate with this IP cause it was came from a DNS query request reply but if the same client want to communicate with IP 567.564.510.945 they can't because it wasn't a DNS query request reply.
Is it possible ?
Thank you very much for any help