<p>Configuring firewall rules based on DNS entries has a very high performance cost. Most vendors who offer this feature caution against using it. Consider what the firewall is really doing here, waiting for DNS resolution to complete before passing traffic. You better have an underutilized multi-core firewall if you're going to attempt that.</p>
↧