Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
William, can you tell me what IP address courier.push.apple.com resolves to, and why you believe this is a dns performance issue?
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
Request URL: http://courier.push.apple.com/
Request Time: 16 Jul, 14:08 (EDT)
Result: Blocked
Reason: Host not found
Policy name: Base Policy
Exceptions: Apple Update, Apple HTTPS
C:\>nslookup courier.push.apple.com
Server: pghpitspwdmc001.-.com
Address: 172.16.-.-
DNS request timed out.
timeout was 2 seconds.
DNS request timed out.
timeout was 2 seconds.
*** Request to pghpitspwdmc001.-.com timed-out
C:\>nslookup courier.push.apple.com 8.8.8.8
Server: google-public-dns-a.google.com
Address: 8.8.8.8
Non-authoritative answer:
Name: courier.push.apple.com
Is there a way to permit traffic through the URL filter (and respect configured exceptions) even if it can't resolve DNS for the destination?The only way would be to skip the proxy for that URL. If the proxy is in transparent mode, you can try adding courier.push.apple.com to the Transparent proxy skiplist as a DNS Host. If using in standard mode, you can add a DIRECT startement to your Proxy.PAC file for the FQDN. When doing either of these, make certain that you have a firewall rule to then allow the traffic.