DNS Firewall Routing for Local Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face protection gaps from cyber threats when accessing local resources outside a protected internal network, as traditional DNS firewalls do not effectively extend protection to mobile devices or external networks, limiting access to internal services.
Innovation Solution
A system where a computing device sends DNS requests through a VPN server to identify with a customer's network block, allowing the DNS firewall to apply protections and direct requests to internal DNS servers for local resource access, ensuring both protection and functionality across networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a DNS firewall is configured to forward global DNS traffic to provide cyber threat protection, then security protection is improved, but user devices outside the internal network lose protection and cannot access local resources
Solution Approach 1:
The DNS request handling is segmented into two distinct paths: one for global DNS requests (forwarded to DNS firewall for security filtering) and one for local DNS requests (handled by internal DNS server). The system determines which path to use based on the request type, allowing simultaneous protection and local resource access.
Solution Approach 2:
The computing device acts as an intermediary between the user device and the DNS infrastructure. It receives DNS requests, determines whether they are global or local, and routes them appropriately to either the DNS firewall or internal DNS server, enabling both security and local resource accessibility.
2Object-affected harmful factors
If DNS requests are forwarded to external DNS firewall server, then security filtering is improved, but access to internal network resources is lost
Solution Approach 1:
The system dynamically adjusts DNS request routing based on the type of request. Local DNS requests are routed to the internal DNS server for easy access to local services, while global DNS requests are routed to the DNS firewall for security filtering. This dynamic routing ensures both security and ease of operation are maintained.
Solution Approach 2:
Different quality of service is applied to different types of DNS requests. Local DNS requests receive direct handling by the internal DNS server for ease of access, while global DNS requests receive security filtering from the DNS firewall. This local quality approach ensures each request type gets the appropriate treatment.
3Adaptability or versatility
If internal DNS server handles all DNS requests, then access to local resources is maintained, but cyber threat protection is lost
Solution Approach 1:
The DNS request handling is segmented into two distinct paths: one for global DNS requests (forwarded to DNS firewall for security filtering) and one for local DNS requests (handled by internal DNS server). The system determines which path to use based on the request type, allowing simultaneous protection and local resource access.
Solution Approach 2:
The computing device provides feedback by determining the origin and type of each DNS request, then routing it appropriately. This feedback mechanism ensures that local requests maintain access while global requests receive security filtering, preventing cyber threats from reaching the internal network.
Data Source
AI summary
Embodiments relate to systems, devices, and computing-implemented methods for resolving DNS requests by sending, from a device, a first DNS request for a domain name associated with a local service device to a DNS firewall server. The DNS firewall server can send a response that includes a status indicating a server failure in response to determining that the first DNS request is associated with a customer of a DNS firewall service and determining that a record associated with the domain name cannot be found. The device can receive the response and send a second DNS request to an internal DNS server in response to the status indicating the server failure.


