[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Lockdown internet using DNS server

Posted on 2011-02-24
1
Medium Priority
?
537 Views
Last Modified: 2012-05-11
I tried something yesterday that didn't work very well and I'm hoping you can spot the error.

A client of ours wanted to lock down the internet for their users while keeping the managers free to do whatever.

There are 2 DNS servers there. One forwards out to the internet and I configured the second as a forwarder to opendns.com. DNS2 was configured as a secondary zone to DNS1. I put the 4 XP computer accounts into their own OU and applied a group policy to assign DNS2 as their DNS server.

When the policy replicated, however, they didn't have access to their main database (hosted on DNS1) or the Internet.

I ended up having to undo the whole solution last night and now we're back where we started - with DNS2 disabled and all machines pointing to DNS1.

What do you guys think?
0
Comment
Question by:taiell0
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 6

Accepted Solution

by:
dr_linux earned 1000 total points
ID: 34969780
The DNS entries should match on both DNS1 and DNS2.  It seems that your main database DNS name was not entered onto your other DNS server.  As long as the entries match, you can set up the other one not to even forward.  Keep in mind this only drops the name resolution, user can still enter the IP addresses and be fine (yes, most users may not even try).
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Ready to improve network connectivity? Watch this webinar to learn how SD-WANs and a one-click instant connect tool can boost provisions, deployment, and management of your cloud connection.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes people don't understand why download speed shows differently for Windows than Linux.Specially, this article covers and shows the solution for throughput difference for Windows than a Linux machine. For this, I arranged a test scenario.I…
BIND is the most widely used Name Server. A Name Server is the one that translates a site name to it's IP address. There is a new bug in BIND (https://kb.isc.org/article/AA-01272), affecting all versions of BIND 9 from BIND 9.1.0 (inclusive) thro…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
Please read the paragraph below before following the instructions in the video — there are important caveats in the paragraph that I did not mention in the video. If your PaperPort 12 or PaperPort 14 is failing to start, or crashing, or hanging, …

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question