Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DNS servers in firewall VMs bypass the Qubes OS firewall #1

Open
3hhh opened this issue Jul 5, 2024 · 0 comments
Open

DNS servers in firewall VMs bypass the Qubes OS firewall #1

3hhh opened this issue Jul 5, 2024 · 0 comments

Comments

@3hhh
Copy link
Owner

3hhh commented Jul 5, 2024

Handling DNS traffic locally via a DNS server inside a firewall VM bypasses the Qubes OS firewall.
So even if the Qubes OS firewall explicitly disallows DNS requests from an upstream VM, the DNS requests of that VM will be answered by the locally running DNS server.

This happens because the Qubes OS firewall only hooks forwarded traffic, but not input traffic (i.e. locally handled traffic).

Unfortunately, since the Qubes OS firewall only calls user scripts before it creates its VM-specific rules, I currently cannot fix this in an elegant way.
I'll see whether the Qubes OS behaviour can be changed so that this issue becomes fixable.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant