Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How do you block/allow domains with revolving/rotating or distributed/geo-dependent DNS?

Our system needs to allow outgoing HTTP/S connections to our Amazon S3 services.  In the past, I was able to create a "DNS Group" object that kept track of the 700+ IP addresses associated with "s3.amazonaws.com" but now after recent firmware updates the DNS Group object is reduced to just one.

I asked Sophos Support about this behavior, and they responded that the DNS Group object was never designed to track all IPs for a domain name with revolving/rotating or distributed/geo-dependent DNS.

Besides entering all of S3's 300 IP blocks manually as network objects (and updating as they change) I was wondering if anyone uses a solution to remedy this behavior?

How do you block/allow a domain name that has revolving or distributed DNS?

Cheers!



This thread was automatically locked due to age.
Parents
  • I may be late with my reply, but just now found this thread and did some lookups (see my screenshot). It's definately amazon who's doing the "changing" ip-addresses.

    Whenever I nslookup s3-1-w.amazonaws.com I get different IP-addresses (and only 1 each time).

    Doing the same for ie mail.office365.com gives a whole bunch of IP's. So this looks like it has nothing to do with UTM dns groups....


    Managing several Sophos UTMs and Sophos XGs both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

    Sometimes I post some useful tips on my blog, see blog.pijnappels.eu/category/sophos/ for Sophos related posts.

  • Arno, that answer was for busthead's question, not for Sam Malone's original post here.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply Children
No Data