Re: Controlling access to web through DNS server



On Mon, 28 Mar 2005 16:40:19 -0500, "Teo" <nospam_teo@xxxxxxxxxxx>
wrote:

>Hey guys!!!
>Hope all of you are doing great.
>I have a situation at a customer of mine that has all of his computers in
>his office looking at a DNS server which is also their exchange server. I
>also placed a firewall on the outside of the company to allow me to give out
>policies to computers connected inside the network and also restrict some of
>them of accesing certain things on the outside.

What firewall did you use? If ISA, did you deploy it on the right
side of the network?

>Now my situation is the following.
>I need to restrit all HTTP, HTTPS, FTP etc excluding POP3 and SMTP from
>every machine on the company. Since all of them look at the Exchange server
>as their DNS server they can go out and surf the web, etc, that is what I
>really don't want. How can I solve this problem so that I can choose which
>computers can access the web and which can't. If I disable the Web policy
>for the DNS server all of the computers will be out, including the mail
>server itself and some power users that I want them to have access to the
>web.

Don't do that. You can restrict the machines from accessing external
addresses via the firewall, and then implement a proxy server such as
ISA or Squid. With DNS, you can still access sites if the user knows
the IP address (and I can get IP addresses for hostnames very easily
in a few seconds, even though my company very helpfully has managed to
block any external DNS queries from being resolved).

Andrew.
--
Andrew Hodgson in Bromyard, Herefordshire, UK.
My Email: use <andrew at hodgsonfamily dot org>.
.



Relevant Pages

  • Re: Can Internet Computers see my private address DNS server?
    ... I have not placed any of our computers in the NAT router's DMZ. ... It is my intent, eventually, to turn the client with the Win Server 2003 ... and there are 6 clients. ... address is entered in the Alternate DNS server: ...
    (microsoft.public.windows.server.dns)
  • Re: W2k Server
    ... I mistakenly set up the 'domain' ad a real ... domain and computers can not join unless I only point the DNS of the ... The computer is an old poweredge server ... should be specifying only the internal DNS server IP anyway - no public IPs. ...
    (microsoft.public.windows.server.general)
  • Re: Computers Kicked off of Domain
    ... The computers are able to login locally ... Event logs give you any clues on the workstations & server? ... no public DNS server IP listed in *any* server or computer's ipconfig. ...
    (microsoft.public.windows.server.general)
  • Wide area failures?
    ... I have a question about the DHCP and the DNS server: ... Assume a company running their own DNS on a windows 2003 server. ... The Wireless network is mapped internally to another private netowork, ... the computers visible. ...
    (microsoft.public.windows.server.dns)
  • Re: DNS and MX records
    ... >Thanks for your reply Andrew! ... >ISA Servers will also be the external DNS Server. ...
    (microsoft.public.windows.server.dns)