nanog mailing list archives

Re: dns interceptors


From: Bill Thompson <Billt () Mahagonny com>
Date: Fri, 12 Feb 2010 16:52:28 -0800

On Fri, 12 Feb 2010 17:32:33 -0500
Jared Mauch <jared () puck nether net> wrote:


On Feb 12, 2010, at 5:15 PM, Randy Bush wrote:

i just lost ten minutes debugging what i thought was a server
problem which turned out to be a dns trapper on the wireless in the
changi sats lounge.  this is not the first time i have been caught
by this.

what are other roaming folk doing about this?

randy

I typically VPN out of broken networks whenever possible.

Operate a VPN/PPTP/IPSEC/squid-proxy/ssh on tcp/80/443 to work around
the issues.

- Jared


Yep, this is what I do as well. It's a little disappointing that you
have to tunnel into a trusted network in order to prevent shenanigans
like that, but it seems to be the way things are.

-- 
Bill Thompson
BillT () Mahagonny com

Attachment: signature.asc
Description:


Current thread: