[c-nsp] policy routing by dest port?

Chuck Church chuckchurch at gmail.com
Tue Nov 12 14:21:06 EST 2013


Wouldn't there be some NATing involved?  Else what is your DNS server going
to do with a destination address that it doesn't own?

Chuck

-----Original Message-----
From: cisco-nsp [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Mike
Sent: Tuesday, November 12, 2013 11:26 AM
To: 'Cisco-nsp'
Subject: [c-nsp] policy routing by dest port?

Hi,

     I have a situation which may require me to reroute all dns traffic in
my network comming from subscribers destined to offsite resolvers, over to
one of my own resolvers instead. The subscribers are all terminated on 7201
and effectively I would like to have a rule I can drop in that says 'dns
traffic to anywhere but my official resolvers is forwarded <here>'. The
subscribers are mostly pppoe which means lots of virtual access interfaces
on the router, and no adjusting the supplied dns servers via ppp won't do (I
need to overcome corrupt / hijacked cpe which are ignoring these values).

Thanks for any pointers.

Mike-

_______________________________________________
cisco-nsp mailing list  cisco-nsp at puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/



More information about the cisco-nsp mailing list