What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

DNS Rebind Protection - on or off?

SkippyP

Regular Contributor
Hello. If using an upstream resolver that already has rebind protection, is it of any value to also keep it enabled on the router? Any harm in keeping it enabled? Does it add significant overhead?
 
You may have it enabled, it won't affect the router's performance in any noticeable way, but you may also get warning messages in system log about possible rebind attack when upstream filtering DNS service blocks something and returns 0.0.0.0 address.
 
Thanks. That’s fine and I’ll keep it enabled. Warning messages in the system log don’t bother me. :)
 
You are perhaps using DoT and filtering upstream DNS resolver. You can keep all three options above "Prevent client auto DoH" to default Disabled state. Keep it simple. Folks like to turn things on/off even when no change is needed just because the option is available.
 
Thanks again. Yes, I’m using DoT to an upstream resolver with filtering (malware protection). The only one enabled is Rebind Protection. The other two settings are disabled. If there’s no harm and no overhead with Rebind Protection, I’ll just leave it enabled.
 
Last edited:
Thanks again. Yes, I’m using DoT to an upstream resolver with filtering (malware protection). The only one enabled is Rebind Protection. The other two settings are disabled. If there’s no harm and no overhead with Rebind Protection, I’ll just leave it enabled.
I've had the Rebind Protection active for years and have never seen any problems. Log fooding has never happened to me, just an occasional message (once or twice a day).
But, to be fair, every connected device is mine and is set up by me, and the messages are only caused by IoT devices that I have only limited control over. As always, ymmv
 

Similar threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top