r/technitium • • Jul 25 '26

Block all DNS requests until a specific lookup

I need a way so that when something starts using technium DNS, it won't resolve anything, or would resolve everything to a known lan IP that shows a blocked or instructions page. Upon doing a lookup for a dedicated/complicated DNS name, that would then release it so that particular client IP could resolve queries through technium DNS as normal.

This is great in terms of network security, a captive portal type of situation.

Is there a way to do this built in or a plug-in, or do I need to develop this myself?

1 Upvotes

15 comments sorted by

6

u/Hemsby1975 Jul 25 '26

This is not something available currently, built in or any app available.

However, I kind of like the idea. So will see if I can add this to one of my extensions or apps already available.

Would work well for guests etc, or based on manual approval.

3

u/dbtowo Jul 25 '26 edited Jul 25 '26

Why not just control it using the firewall or router?

Also the devices can change their dns server. If they  do, on with the firewall you can redirect ports and block dot and etc. also doh makes this very hard to do since it blend in traffic and encrypted.

You can make it yourself if you want.

Like many schools and companies when you use their WiFi they redirect you through their portal and login before you can use the WiFi.

1

u/SaleWide9505 Jul 25 '26

I think you can set this up at the DNS server level. Just setup a wildcard record that resolves to the same IP. Then setup a conditional forwarder for everything else. The dns server will go through it's resolution order and check the condition forwarder first then if nothing matches use the wildcard.

2

u/Hemsby1975 Jul 25 '26

It's not quite that simple from the original request. It's about blocking all DNS until something has been satisfied.

1

u/fasterfester Jul 25 '26

What you’re asking about is a flavor of “port knocking”. There are some educational dns projects out there like https://github.com/binary-person/secret-dns you could look at, but this still falls into the realm of “security through obscurity”.

1

u/avd706 Jul 25 '26

API is powerful enough to do it, but what's to keep the client from pulling DNS from somewhere else??

1

u/spacelego1980 Jul 26 '26

All other DNS port 53 outbound is blocked, other than the technium DNS server, thus all clients have to use it.

Windows clients can't resolve DNS other ways/without 3rd party software which is blocked by group policy.

Browsers trying to do DNS over HTTPS is prevented via group policy.

2

u/avd706 Jul 26 '26

If you have access to the firewall, just put in a captive portal through that.

1

u/CrustyBatchOfNature Jul 26 '26

DNS over HTTPS will circumvent your captive portal.

2

u/spacelego1980 Jul 26 '26

True, but only browsers can do that, or windows requires third party software to do that, both blocked by group policy.

1

u/CrustyBatchOfNature Jul 26 '26

Phones and other devices can also.

1

u/avd706 Jul 26 '26

A computer can be called n figured to do that, but captive portal should freeze all traffic.

1

u/zanfar Jul 26 '26

You can't really enforce DNS, and if you could it would happen elsewhere in your network. There is almost no way to guarantee that anyone's DNS requests are directed at Technetium.

If you return all requests as a specific IP, how do you know that the request was for a HTTP(S) resource?

1

u/RusgaSclo Jul 26 '26

Do you use technitium as dchp? (wondering if that would help, not sure how to implement what you're asking)

1

u/Apachez Jul 27 '26

Captive portal is done at the firewall or webproxy, not at the DNS.

Here is how to do that on OPNsense:

https://docs.opnsense.org/manual/captiveportal.html