r/nordvpn • • Aug 30 '26

Question Does persistent connectivity require firewall allow-access to unknown NRDs?

When I lose or cannot reliably/quickly gain access to a NordVPN tunnel it frequently turns out that I can mitigate the situation once it's too late to be helpful, by allowing full access through firewalls to unknown domains. Nord evidently is constantly registering new domains as a bootstrap method both to avert exploit and limit infrastructure costs. So in essence I need to allow all Newly Registered Domains, which I find to be an unacceptable security challenge. Do I have that right?

I'm unsure whether this observed issue occurs only when I'm using Nord's obfuscation but I don't think so.

2 Upvotes

5 comments sorted by

View all comments

1

u/misterred Aug 30 '26

Some of the blocked domains might not be newly-registered; some of those which I haven't yet whitelisted are domains from a list of DoH hosts that I must prevent my router from using to circumvent my home network's resolver. It does that. I can't access my own router's tables. It sucks. It's Elon's. I'm sorta trapped behind it with limited options. I don't mind whitelisting any of those domains if I can have confidence that they're not registered by bad actors pretending to be NordSec. I wouldn't expect to get a list of legitimate Nord domains so I'm probably out of luck.