Closed bruvv closed 4 years ago
Adguard has two built-in features to protect against DNS amplification attacks:
ANY
queries, which is enabled by default. ANY
queries are on the verge of being deprecated, because they are rarely used in real world scenarios yet quite resource heavy (see: https://blog.cloudflare.com/rfc8482-saying-goodbye-to-any/)Because of this, I've chosen not to include the iptables commands, as the above does more or less the same and is easier to configure.
When having a public DNS server it's important to have it setup relative save. That can be done with 3 easy iptable commands:
More info from your website ;) https://freek.ws/2017/03/18/blocking-dns-amplification-attacks-using-iptables/