mdns-filoxy
This is mdns-filoxy, the mDNS filter proxy!
Table of contents
Introduction
Welcome to mdns-filoxy, the mDNS filter proxy.
What is it for?
mdns-filoxy allows you to send configured mDNS service queries out a specified interface, cache the response, and
then listen for further queries and answer them on a different interface.
This is particularly useful when you (rather smartly) put your IoT devices in a different network/VLAN to your "main" network. I have my Sonos speakers setup this way, and without some form of proxy, I simply cannot talk to them anymore, because of their odd use of mDNS and SSDP, and 14,000 other convoluted methods to reach their ecosystem.
But isn't that what avahi-daemon et al are for?!
avahi-daemon does have a reflector mode, and there are other packages like mdns-repeater. The issue is that they
both
listen for queries and then just re-send them out other interfaces. avahi-daemon even lets you filter reflections,
but they don't allow you to control the direction of the reflecting.
Furthermore, in the case where you have some other server on the same networks, with two or more interfaces bound to it,
systemd can have
a rather major meltdown whilst it tries to think for you and
choose unique mDNS names. A good example of this is Home Assistant's HAOS.
systemd behaves badly with mdns repeaters too.
Draw me a picture
Ok. Lets pretend you have a phone that sits in a VLAN, connected to a firewall interface called eth0 (known as the
dest-interface). Lets further pretend your Sonos speaker is in another VLAN, connected to iot0 (known as the
--source-interface).
When mdns-filoxy starts, it will bind to the specified interfaces, and on the source interface will query for the
chosen services (--mdns-services):
flowchart LR
Firewall -->|iot0| mc[Multicast to VLAN
query for mdns-services] --> sonos[Speakers respond]-->|iot0 reply| Firewall
mdns-filoxy caches that response, and then lies in wait, ready to respond to any queries that arrive on eth0.
Once mdns-filoxy is up and listening, here's the sequence of events:
flowchart LR
phone[Phone
Sonos app
launched] --> mc[Multicast to VLAN
query for _sonos._tcp.local.] -->|eth0| Firewall -->|eth0 reply| phone
Notice that the queries and responses aren't bi-directional, and this is intentional. The software is meant to give minimal assistance to mDNS/IoT devices to get bootstrapped and then on with whatever other evil protocol(s) they use.
What's with the name?!
filoxy is my blend of "filter" and "proxy", as that's basically what this software does.
Installation
The recommended way to install mdns-filoxy is to use pipx.
After getting pipx installed, simply run:
username@host:~$ pipx install mdns-filoxy
You can of course also install it using classic virtualenvs.
License
mdns-filoxy is distributed under the terms of the MIT license.
Metadata
Release files for mdns-filoxy 1.0.6
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| mdns_filoxy-1.0.6.tar.gz | 1.4 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| mdns_filoxy-1.0.6-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.5 MB
Release files / mdns_filoxy-1.0.6.tar.gz
| Download URL | mdns_filoxy-1.0.6.tar.gz |
|---|---|
| Size | 1.4 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
084e7aeed9ec6d5a83c0c33ab113fd2285852de53d9febf528f32e87e216c017
|
|
BLAKE2b-256 checksum How to use checksums |
9f255efc07a2ca4424fb79990affb45b598b6eef2498195d708a90f7324dde7d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on May 26, 2026.
Transparency logRelease files / mdns_filoxy-1.0.6-py3-none-any.whl
| Download URL | mdns_filoxy-1.0.6-py3-none-any.whl |
|---|---|
| Size | 6.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
54368f63bc869456cf868f4241aefcc365b7a44e55b9253947582306e36134f9
|
|
BLAKE2b-256 checksum How to use checksums |
e35af86e95d2dc733b781fcab448da72ba378814071a4385a1285e8633d413ac
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on May 26, 2026.
Transparency log