Re: DNS on w2k - Internal Only

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Kevin D. Goodknecht Sr. [MVP] (admin_at_nospam.WFTX.US)
Date: 08/05/04


Date: Thu, 5 Aug 2004 09:22:15 -0500

In news:5dde95d2.0408041055.4eff2f41@posting.google.com,
Randy Henson <rhenson@cellxion.com> wrote their comments
Then Kevin replied below:
> dns is working fine, however, I have some clients that
> are not to have internet access, but I haven't been able
> to track down how to make the dns server internal only.

You need for DNS to do all resolution for all clients even if the client
does not have internet access.
Probably the easies way to prevent those clients from accessing the
internet, is to set up a dummy Proxy address on those clients. You can do
this through group policy by creating a new OU (call it NoNet if you want)
for the users/clients you don't want accessing the net and move those
users/clients to that OU, then right click on the OU select properties,
Group Policy tab, New, name the Policy then select Edit. Expand User
Configuration, Windows Settings, Internet Explorer Maintenance. Select
Connection then double click Proxy Settings. Then if it is the Machine
expand Computer Configuration, Administrative Templates, Windows Components
and select Internet Explorer. Double Click "Make proxy settings per-machine
(rather that pre-user) and enable the policy.

Once the Policy is set up any account you put in the OU will get the dummy
proxy address which will only get them a Socket Error. OE does not use the
Proxy setting so, they _can_ still get e-mail, just not if the content
requires http, ftp, SSL, etc.

-- 
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
================================================
-- 
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
================================================
http://www.lonestaramerica.com/
================================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
================================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
================================================


Relevant Pages

  • Group Policy Connundrum - Stick with it, its confusing!!!
    ... I have created a policy named no internet. ... I have also created some exceptions for this policy, which do not use the proxy, i.e. ... Then by setting the 'Admin Template> Windows Components> Internet Explorer> Disable Changing Proxy Settings' to enabled effectively grays out the proxy settings in internet explorer and stops the user from altering the settings. ...
    (Security-Basics)
  • Group Policy Connundrum - Stick with it, its confusing!!!
    ... I have created a policy named no internet. ... I have also created some exceptions for this policy, which do not use the proxy, i.e. ... Then by setting the 'Admin Template> Windows Components> Internet Explorer> Disable Changing Proxy Settings' to enabled effectively grays out the proxy settings in internet explorer and stops the user from altering the settings. ...
    (Security-Basics)
  • Re: ISA Server Problems, please help
    ... > clients are unaffected, is it secureNAT clients which are affected? ... then checked Send the original host header to the publishing server instead ... > provided unrestricted internet access. ...
    (microsoft.public.windows.server.sbs)
  • Re: Cant RDP to severs desktop through RWW
    ... I understand that the issue occurs both in LAN and the Internet, ... 'Microsoft Firewall' service. ... Does this issue occur to all clients or several clients? ... I get the same error message ...
    (microsoft.public.windows.server.sbs)
  • Re: After installing SBS 2003 two IE 6.0.29 SP2 clients that cannot to companyweb
    ... Mozilla, and other clients can access the http://comanyweb, the SBS server ... Reset the Internet Explorer Settings to Default. ... DHCP was turned off in SBS 2003. ...
    (microsoft.public.windows.server.sbs)