Solved

Editing DNS to block Facebook

Posted on 2010-09-09
7
886 Views
Last Modified: 2012-05-10
Our company has decided to block Facebook plus various other social networking sites.

I have amended a hosts file which seem to do the trick. However I need to role this out to 80 users. I understand that this can be done via group policy. However, i've also seen people suggest that web sites can be blocked via entries in my windows DNS servers.

Can anybody let me know what I need to do to the DNS to achieve this?
0
Comment
Question by:metamatic
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 2

Expert Comment

by:dannyyo
ID: 33638084
I believe you can just add a "New Host" for that site.  If this is a company, the best way to do it would be to use a firewall with content filtering.  We use sonicwall content filtering at our office and all you have to do is deny the whole category of social networking.
0
 
LVL 5

Expert Comment

by:Swapnil Prajapati
ID: 33638091
You can goto DNS on your server right click Goto Forwarders
Add new forwarder and say it as facebook.com domain give forwarder ip as 127.0.0.1

Once you do it the queries for facebook.com should resolve to local and it should be blockec.
0
 
LVL 3

Expert Comment

by:kf4zmt
ID: 33638092
Create a new zone on your dns server called facebook.com and then create an A record that points to a bogus IP address.
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 5

Accepted Solution

by:
CWCertus1 earned 500 total points
ID: 33638099
Create a zone called facebook.com and add a www A (host) record pointing somewhere else i.e. 127.0.0.1.

Any user with enough rights on their own machine could get the IP address of the facebook and create a www.facebook.com entry in their own hosts file to get around this.

A better solution would be to use group policy to push internet explorer settings which prevent this (content adviser or trusted sites lockdowns etc.) or buy a purpose made solution for this e.g. webmarshal softwar or a hosted solution like websense - incidentally you can force users to use websense on their work machines at home as it is hosted and they would then have to abide by work guidelines for browsing on company machines at all times.
0
 
LVL 12

Expert Comment

by:mccracky
ID: 33639692
Put the new DNS server in the DHCP configuration and it should be pushed out automatically as each machine renews it's IP address lease with the DHCP server.
0
 
LVL 12

Expert Comment

by:mccracky
ID: 33639711
Then to make sure that no one uses another DNS to get around the filter, you can block outgoing port 53 (DNS) on your firewall for every machine except your server.
0
 
LVL 12

Expert Comment

by:mccracky
ID: 33639773
Rereading your question, if depends if you host your own DNS server or use another one (like one provided by your ISP).  If you host your own, then you put in a forwarder like someone mentioned above.  If you use your ISP, then you can switch to something like OpenDNS.  Anyway, the way to push out the DNS settings would be through your DHCP server.
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, I had the need to build a standalone system to run a point-of-sale system. I’m running this on a low-voltage Atom processor, so I wanted a light-weight operating system, but still needed Windows. I chose to use Microsoft Windows Server 200…
I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that. In this Article I'll show how to deploy printers automatically with group policy and then using security fil…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question