Announcement

Collapse
No announcement yet.

Request: Move DoH Blocking from System-Level to Policy-Based Category

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Request: Move DoH Blocking from System-Level to Policy-Based Category

    Hello,

    I'd like to request a change regarding how DoH (DNS over HTTPS) is currently being blocked on the Nxcloud server.

    At the moment, DoH is being blocked at the system level, through the file "/nxcloud/conf/system-block.txt". This approach blocks DoH for all users on the network without exception.

    Could we instead configure this as a "Blocked Category" policy rather than a system-wide block? The reason for this request is that I have different groups of users with different needs:

    - Some users rely on Apple's DoH for added security and privacy, and this is currently being blocked on my network.
    - Other users still need to have DoH blocked.

    Moving this to a policy-based block would allow us to apply DoH restrictions selectively per group/category, instead of enforcing a single rule for everyone.

    Please let me know if this is feasible and what steps would be needed to implement it.

    Thank you,

  • If you allow users to bypass filtering, what's the point of filtering in your network? That's the problem.

    There's a workaround though. Move all the domains or the domains you need in the file into a custom category 'User DoH domains' and allow them in a policy.

    Comment

    Working...
    X