假設今天用iptable drop www.google.com
iptable command:
iptables -I FOEWARD -m string --string “google.com" --algo bm -j DROP
但卻無法擋住(drop)www.google.com ...
此問題要從DNS Query看起,DNS Query有兩種方式:
- HTTP2.0: DNS Query → TCP handshake → TLS handshake
- HTTP3.0: DNS Query → QUIC handshake