Solved

Editing DNS to block Facebook

Posted on 2010-09-09
7
883 Views
Last Modified: 2012-05-10
Our company has decided to block Facebook plus various other social networking sites.

I have amended a hosts file which seem to do the trick. However I need to role this out to 80 users. I understand that this can be done via group policy. However, i've also seen people suggest that web sites can be blocked via entries in my windows DNS servers.

Can anybody let me know what I need to do to the DNS to achieve this?
0
Comment
Question by:metamatic
7 Comments
 
LVL 2

Expert Comment

by:dannyyo
ID: 33638084
I believe you can just add a "New Host" for that site.  If this is a company, the best way to do it would be to use a firewall with content filtering.  We use sonicwall content filtering at our office and all you have to do is deny the whole category of social networking.
0
 
LVL 5

Expert Comment

by:Swapnil Prajapati
ID: 33638091
You can goto DNS on your server right click Goto Forwarders
Add new forwarder and say it as facebook.com domain give forwarder ip as 127.0.0.1

Once you do it the queries for facebook.com should resolve to local and it should be blockec.
0
 
LVL 3

Expert Comment

by:kf4zmt
ID: 33638092
Create a new zone on your dns server called facebook.com and then create an A record that points to a bogus IP address.
0
3 Use Cases for Connected Systems

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, testing some more, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us.

 
LVL 5

Accepted Solution

by:
CWCertus1 earned 500 total points
ID: 33638099
Create a zone called facebook.com and add a www A (host) record pointing somewhere else i.e. 127.0.0.1.

Any user with enough rights on their own machine could get the IP address of the facebook and create a www.facebook.com entry in their own hosts file to get around this.

A better solution would be to use group policy to push internet explorer settings which prevent this (content adviser or trusted sites lockdowns etc.) or buy a purpose made solution for this e.g. webmarshal softwar or a hosted solution like websense - incidentally you can force users to use websense on their work machines at home as it is hosted and they would then have to abide by work guidelines for browsing on company machines at all times.
0
 
LVL 12

Expert Comment

by:mccracky
ID: 33639692
Put the new DNS server in the DHCP configuration and it should be pushed out automatically as each machine renews it's IP address lease with the DHCP server.
0
 
LVL 12

Expert Comment

by:mccracky
ID: 33639711
Then to make sure that no one uses another DNS to get around the filter, you can block outgoing port 53 (DNS) on your firewall for every machine except your server.
0
 
LVL 12

Expert Comment

by:mccracky
ID: 33639773
Rereading your question, if depends if you host your own DNS server or use another one (like one provided by your ISP).  If you host your own, then you put in a forwarder like someone mentioned above.  If you use your ISP, then you can switch to something like OpenDNS.  Anyway, the way to push out the DNS settings would be through your DHCP server.
0

Featured Post

Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Recently, I had the need to build a standalone system to run a point-of-sale system. I’m running this on a low-voltage Atom processor, so I wanted a light-weight operating system, but still needed Windows. I chose to use Microsoft Windows Server 200…
Occasionally you run into the website or two that will not resolve properly using your own DNS servers.  Some people simply set up global forwarders for their DNS server.  I don’t recommend doing this because it can cause problems resolving addresse…
I designed this idea while studying technology in the classroom.  This is a semester long project.  Students are asked to take photographs on a specific topic which they find meaningful, it can be a place or situation such as travel or homelessness.…
A company’s greatest vulnerability is their email. CEO fraud, ransomware and spear phishing attacks are the no1 threat to a company’s security. Cybercrime is responsible for the largest loss of money to companies today with losses projected to r…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

7 Experts available now in Live!

Get 1:1 Help Now