Solved

Lockdown internet using DNS server

Posted on 2011-02-24
1
534 Views
Last Modified: 2012-05-11
I tried something yesterday that didn't work very well and I'm hoping you can spot the error.

A client of ours wanted to lock down the internet for their users while keeping the managers free to do whatever.

There are 2 DNS servers there. One forwards out to the internet and I configured the second as a forwarder to opendns.com. DNS2 was configured as a secondary zone to DNS1. I put the 4 XP computer accounts into their own OU and applied a group policy to assign DNS2 as their DNS server.

When the policy replicated, however, they didn't have access to their main database (hosted on DNS1) or the Internet.

I ended up having to undo the whole solution last night and now we're back where we started - with DNS2 disabled and all machines pointing to DNS1.

What do you guys think?
0
Comment
Question by:taiell0
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 6

Accepted Solution

by:
dr_linux earned 250 total points
ID: 34969780
The DNS entries should match on both DNS1 and DNS2.  It seems that your main database DNS name was not entered onto your other DNS server.  As long as the entries match, you can set up the other one not to even forward.  Keep in mind this only drops the name resolution, user can still enter the IP addresses and be fine (yes, most users may not even try).
0

Featured Post

Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

It is only natural that we all want our PCs to be in good working order, improved system performance, so that is exactly how programs are advertised to entice. They say things like:            •      PC crashes? Get registry cleaner to repair it!    …
I've written instructions for one router type, but this principle may be useful for others of the same brand and even other brands of router. Problem: I had an issue especially with mobile devices that refused to use DNS information supplied via…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Suggested Courses

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question