How NOT to provide external name resolution on win2k3?



We have a domain with 2 windows 2003 servers as domain controllers that are
also providing DNS services. Workstations within the domain are a
combination of windows xp and also legacy systems running windows nt. The
workstations point to these 2 servers as their preferred dns servers.

We recently discovered that the workstations can resolve internet addresses
with no problem. While we don't actually mind that the workstations have
internet access, we'd like to make it difficult for them to resolve internet
addresses.

At first I thought it was strange that the workstations were able to resolve
internet addresses in Internet Explorer because the servers don't have any
forwarders configured. The servers did however point to 2 "external
capable" dns servers as their numbers 3 and 4 dns servers. (The first 2
being themselves.)

I removed the entries of the external dns servers that were bound to the nic
card, and deleted the entries in the root hints list in the dns
properties. Well this seemed to have stunned it momentarily, but after a
few minutes the servers were again able to browse the internet. Is there
any easy way to change this so that the servers and the workstations cannot
resolve names enough to browse the internet?

Thanks, Joel


.



Relevant Pages

  • Re: How Secure is ".Local?"
    ... > dozen servers and ~500 websites/public domains. ... Shadow DNS ... Is your DC on the Internet? ... >>It is not going to provide your zone info to anyone ...
    (microsoft.public.win2000.dns)
  • RE: New Forest - Old Domain - Plus DMZ - Help Please
    ... Make sure Windows XP client should use the AD DNS ... The Cert should match the name in Internet. ... New Forest - Old Domain - Plus DMZ - Help Please ... vast majority of our inside production equipment is 2003 servers and XP ...
    (microsoft.public.windows.server.migration)
  • Re: Active Directory and child DNS Zone
    ... > Our internal and external DNS domains are both the same - mycompany.com. ... > hosts our external domain and it only contains entries for our web servers ... >>> but the test bed isn't a true picture (no internet access to test VPN, ...
    (microsoft.public.windows.server.dns)
  • Re: Very Slow(60mins) XP logon
    ... The DNS on the servers is set to internal only, workstations get their dns through dhcp which also sets them up for internal dns. ... The slow logon happens with any AD account. ...
    (microsoft.public.win2000.networking)
  • Re: DNS design questions
    ... We're a medium size college campus with about 10,000 users and the CIO wants to have DNS locally housed. ... only a hand full to a few dozen max "Internet servers" while ... how big of a security issue really is allowing the "external" DNS server pull a zone transfer from an internal one? ...
    (microsoft.public.windows.server.dns)