local.rules:
# ByPass DNS known dns servers
pass udp $DNS_SERVERS 53 → any any (bypass; sid:100000050; rev:1; )
pass udp $HOME_NET any → $DNS_SERVERS 53 (bypass; sid:100000051; rev:1; )
Ok, thanks, need some help with that.
Would this disable all dns, or dns query and answer logging?
config dns $DNS_SERVERS any → any any (dns.answer; config: logging disable, type tx, scope tx; sid:1;)
config dns any any → $DNS_SERVERS any (dns.query; config: logging disable, type tx, scope tx; sid:1;)
Or all:
config dns $DNS_SERVERS any → any any (config: logging disable, type tx, scope tx; sid:1;)
config dns any any → $DNS_SERVERS any (config: logging disable, type tx, scope tx; sid:1;)
pass dns $DNS_IB any → any any (bypass; sid:100000050; rev:2; )
pass dns any any → $DNS_IB any (bypass; sid:100000051; rev:2; )
config dns $DNS_IB any → any any (config: logging disable, type tx, scope tx; sid:100000052;)
config dns any any → $DNS_IB any (config: logging disable, type tx, scope tx; sid:100000053;)