USG310 - 4.62(AAPJ.0): Wildcard FDQN seems not to be working for routing!
for example, I wish to allow/redirect all traffic to *.fbcdn.com to another link, I have this working listing each and every domain/subdomain, however, the wild card option seems not to be working.
![Image: https://us.v-cdn.net/6029482/uploads/editor/ou/xhwi9fzikf1r.png](https://us.v-cdn.net/6029482/uploads/editor/ou/xhwi9fzikf1r.png)
![Image: https://us.v-cdn.net/6029482/uploads/editor/np/rcpwalssf3g6.png](https://us.v-cdn.net/6029482/uploads/editor/np/rcpwalssf3g6.png)
I have made the appropriate wild cards but as said these seem not to work, Is it possible for someone to advise how I'm supposed to use this feature?
Best Answers
-
Ok something to keep in mind about Wildcard FDQN vs non-Wildcard FDQN as non-wildcard are looked up by the USG and Wildcard FDQN are found by DNS lookups done to the USG or though the USG so if a client uses say Firefox with DNS over HTTPS the USG will not see the lookups.
0 -
So you got clients connect by VPN to the USG?
Can you not run a bind server where DNS is in the clear?0
All Replies
-
a small correction: for example, I wish to allow/redirect all traffic to *.fbcdn.com to another link, I have this working listing each and every domain/subdomain, however the wild card option seems not to be working.0
-
Ok something to keep in mind about Wildcard FDQN vs non-Wildcard FDQN as non-wildcard are looked up by the USG and Wildcard FDQN are found by DNS lookups done to the USG or though the USG so if a client uses say Firefox with DNS over HTTPS the USG will not see the lookups.
0 -
PeterUK said:
Ok something to keep in mind about Wildcard FDQN vs non-Wildcard FDQN as non-wildcard are looked up by the USG and Wildcard FDQN are found by DNS lookups done to the USG or though the USG so if a client uses say Firefox with DNS over HTTPS the USG will not see the lookups.
0 -
So you got clients connect by VPN to the USG?
Can you not run a bind server where DNS is in the clear?0 -
PeterUK said:So you got clients connect by VPN to the USG?
Can you not run a bind server where DNS is in the clear?
https://github.com/pi-hole/pi-hole/wiki/DNSCrypt-2.0
https://github.com/pi-hole/pi-hole
0
Categories
- All Categories
- 413 Beta Program
- 2.3K Nebula
- 192 Nebula Ideas
- 87 Nebula Status and Incidents
- 5.3K Security
- 142 USG FLEX H Series
- 253 Security Ideas
- 1.3K Switch
- 75 Switch Ideas
- 993 Wireless
- 51 Wireless Ideas
- 6.1K Consumer Product
- 231 Service & License
- 362 News and Release
- 74 Security Advisories
- 23 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 101 About Community
- 67 Security Highlight