G
G
Grant2k2017-05-21 20:47:20
Mikrotik
Grant2k, 2017-05-21 20:47:20

Is it possible to statically route to a name rather than an ip address in microtik?

Hello
The task is to launch banned sites via vpn, the rest
is not an option through the provider according to IP addresses, because there are many
. Is it possible to route certain sites to a specific channel? Any ideas?

Answer the question

In order to leave comments, you need to log in

4 answer(s)
D
Dmitry Shitskov, 2017-05-21
@Zarom

Just an idea. Take as a basis for a solution, for example, this article .
But instead of blocking traffic, put labels and route labels wherever you need.

D
Diman89, 2017-05-22
@Diman89

Create an address list with banned sites by domain name, and route the list via vpn with mangle. Names in ip when using vpn will be cut off correctly

H
HawK, 2017-05-22
@HawK3D

The technical specialists of most providers are people who can think systematically, their ideological literacy is an order of magnitude higher than that of their leaders and government agencies. They have an understanding that any restrictions in a single state not only contradict the very essence of the Internet as a supranational phenomenon, but are also practically impossible and meaningless, therefore the requirement of state bodies to block is carried out only formally, to the extent that blocking is guaranteed to work regarding those who initiate such blocking)
Have you tried to figure out the mechanism of blocking at your provider? Usually solved by specifying any public dns-server instead of the provider. How to neutralize Rostelecom blocking can be found here. In the case of other providers, you need to analyze the traffic and configure MikroTik accordingly. In general, if a provider blocks "tightly", it is worth considering why this provider blocks to a greater extent than required by Roskompozor and dooms its subscribers to additional costs and difficulties associated with vpn, etc.

G
Grant2k, 2017-05-22
@Grant2k

Our Kyivstar killed dns and something else, most likely something like if the destination address is "VKontakte" port 80 or 443 - deny, and the tracer goes

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question