Community discussions

MikroTik App
 
Rivera
Member Candidate
Member Candidate
Topic Author
Posts: 105
Joined: Thu Jul 21, 2011 7:42 pm

Feature request: support for DNS in packages

Sat Nov 19, 2011 8:23 pm

Really anoying part i that i should put, for example, IP for VPN servers.
Many providers have vpn server address as domain name, for example vpn.corbina.net. And they sometimes changing. And more than that - there is servers in rotation, so if one of them will fail, resolver can pick another and connect. Not in routeros, anyway...

So i ask for adding domains support in every place where it can be used -
1. tunnels (ipip, gre, etc) - for example for connecting remote offices i can use gw1...gw2 subdomains
2. VPN clients (already described)
3. NTP client (pool.ntp.org will pick best server)
4. Remote logging
 
pedja
Long time Member
Long time Member
Posts: 684
Joined: Sat Feb 26, 2005 5:37 am

Re: Feature request: support for DNS in packages

Sun Nov 20, 2011 8:59 am

Asked lots of times before. This request is several years old, actually. They simply refuse to do that. Reasons unknown.
 
User avatar
janisk
MikroTik Support
MikroTik Support
Posts: 6263
Joined: Tue Feb 14, 2006 9:46 am
Location: Riga, Latvia

Re: Feature request: support for DNS in packages

Mon Nov 21, 2011 12:12 pm

we are considering to allow to enter domain name instead of IP address. but the problem start when this IP is entered in somewhere like firewall where a lot of traffic and it has to be resolved over and over again. that goes for logging and firewall. So in these 2 and similar places, it most probably will not happen.
 
Rivera
Member Candidate
Member Candidate
Topic Author
Posts: 105
Joined: Thu Jul 21, 2011 7:42 pm

Re: Feature request: support for DNS in packages

Mon Nov 21, 2011 12:53 pm

why firewall? I primary ask for VPN support.
 
User avatar
CristianDeluxe
Frequent Visitor
Frequent Visitor
Posts: 53
Joined: Fri Jun 05, 2009 10:59 am
Location: Spain
Contact:

Re: Feature request: support for DNS in packages

Thu Dec 15, 2011 10:29 pm

we are considering to allow to enter domain name instead of IP address. but the problem start when this IP is entered in somewhere like firewall where a lot of traffic and it has to be resolved over and over again. that goes for logging and firewall. So in these 2 and similar places, it most probably will not happen.
Why no cache the dns resolve in a "variable" with a "timeout" value?

ie:
/ip firewall mangle
add action=accept chain=prerouting disabled=no src-address=mikrotik.com
1st packet:

[in] ------> [mangle] ------> [domainfound] ------> [cacheddns?] ------> [no] ------> [resolve dns] ------> [internal cache domain ip for x time] ------> [apply mangle rule] ------> [out]

2nd packet:

[in] ------> [mangle] ------> [domainfound] ------> [cacheddns?] ------> [yes] ------> [read ip from cache (more faster than resolve)] ------> [apply mangle rule] ------> [out]

[...]

When the time for cache expires RouterOS resolve the dns again, this timeout must be edited by users so some people with lot of rules can give it a big timeout (ie: 10d) and people with small rules or that are using it only with VPN, NTP can give it a small timeout (some hours)

Who is online

Users browsing this forum: Bing [Bot], Kindis, memo009525 and 110 guests