2
Votes

Proposal to Enhance the DNS Cache Function in the Omada System

 
2
Votes

Proposal to Enhance the DNS Cache Function in the Omada System

Proposal to Enhance the DNS Cache Function in the Omada System
Proposal to Enhance the DNS Cache Function in the Omada System
a week ago
Model: ER8411  
Hardware Version: V1
Firmware Version:

The current implementation of DNS Cache in Omada significantly improves network performance and reduces WAN load. However, a few additional features could make it even more useful:

  1. Information about the active WAN interface

    • Display which WAN connection is currently being used by the system when handling DNS Cache.

    • This would be especially helpful in multi-WAN setups (failover/load balancing), where administrators need to easily verify through which WAN the DNS queries are being processed.

  2. Option to block specific entries in the DNS Cache

    • Allow administrators to manually mark or block specific domains considered suspicious or unwanted.

    • This would act as a simple security filter at the Omada Gateway level.

    • It would enable quick reactions to newly emerging threats (e.g., phishing, malware) before they are blocked by external services.

With these enhancements, DNS Cache in Omada would not only serve as a tool for accelerating network performance, but also as an additional security layer that improves the overall protection of the infrastructure.

#1
Options
4 Reply
Re:Proposal to Enhance the DNS Cache Function in the Omada System
a week ago

3. Integration with external APIs for diagnostics

  • For example, leveraging the ipinfo.io API could greatly improve DNS-related diagnostics and threat analysis.
  • As a final touch, this data could be visualized on the Global View > Security map, providing administrators with a clearer and more intuitive overview of potential threats worldw
#2
Options
Re:Proposal to Enhance the DNS Cache Function in the Omada System
a week ago - last edited a week ago

  @Pablo_PL 

 

Seconded point 1 with a twist - allow us to actually select which WAN the DNS proxy reaches out to our chosen servers to (if they are external IPs and not an internal resolver)

 

My current workaround for this is a IP Group with my chosen DNS revolvers in, policy routed to a specific WAN.   I have no idea if this actually works with DNS proxy since its not really traffic coming from the LAN but it makes me feel a bit better 

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
#3
Options
Re:Proposal to Enhance the DNS Cache Function in the Omada System
a week ago

  @Pablo_PL 

 

and adding a point 4 -

 

Allow us to select either networks or IP ranges (Manual input of IP ranges would be fine (like on VPNs) so we dont have to use up yet more IP Groups) when the Proxy is set to "Override" mode so we can also apply it to switch routed lans that are not directly hoseted on the gateway (or it has an interface on at least)

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
#4
Options
Re:Proposal to Enhance the DNS Cache Function in the Omada System
a week ago

  @GRL 

 

and add point 5 

It would also be useful to have the option to search entries, just like in other Omada windows.

#5
Options