Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

How best to block all IP traffic to the new .XXX domains

Posted on 2011-09-09
7
Medium Priority
?
1,286 Views
Last Modified: 2012-05-12
In a Microsoft Windows Server 2003 AD network, is it possible to use Microsoft DNS to block access to all subdomains of the new .XXX TLD? The firewall router is not capable of URL filtering.
0
Comment
Question by:askrabbit
7 Comments
 
LVL 9

Accepted Solution

by:
Chev_PCN earned 1600 total points
ID: 36509463
You can't use DNS to actively block. You CAN stop it from resolving through.
It's as simple as creating a zone for XXX and leaving it empty.
What this does, is it makes your DNS organisation authoritative for that domain (i.e. the only one that can do resolution), so if a client asks for a XXX address, it will come back blank.
Unfortunately if a client uses the IP address, they can still access the site.
You would be best putting in a proxy of some sort.  Free, powerful & easy to administer is squid.
0
 
LVL 14

Expert Comment

by:setasoujiro
ID: 36509869
another thing to consider is that people could still use a public dns , instead of your own.
Unless you blocked their ability to change their dns settings
0
 
LVL 26

Expert Comment

by:Soulja
ID: 36510150
What type of firewall/ router do you have?
0
Ready for your healthcare security check-up?

In the past few years, healthcare organizations have become a prime target for advanced attacks. Does your organization have what it needs to defend itself? Schedule your healthcare security check-up today and download our free Healthcare Security Resource Kit today!

 
LVL 2

Author Comment

by:askrabbit
ID: 36510153
Chev_PCN, we did in fact try your suggestion already, but without success. However, I have realised that I was making a mistake when testing by using a fictitious xxx domain/host. I discovered that porn.xxx and sex.xxx are "Safe for Business" placeholder sites. When I used these for testing, I found that the disruption to DNS resolution works fine. Thank you! I understand your point about direct access via IP address. Also, there are plenty of porn sites on .com, etc which would still be accessible. Still, the client asked me a specific question...

Thank you for your comment about proxies. This is also under consideration.

setasoujiro, Fair point, although most users are not local admins and so would not be able to change any workstation IP settings.
0
 
LVL 14

Assisted Solution

by:setasoujiro
setasoujiro earned 400 total points
ID: 36510271
yeah but they could also just use an online proxy if they really have the pornurge :)
and if this is such a concern to your company i would strongly advice to purchase a webblocking capable device , I can safely say that watchguard offers a strong webblocker/application blocker combined with firewall/Antispam etc,  and is not too expensive either
0
 
LVL 2

Author Comment

by:askrabbit
ID: 36521507
Thank you to both of you for your comments. I have certainly told the company that just focussing on .XXX does not mean no porn... ;-)
0
 
LVL 2

Author Closing Comment

by:askrabbit
ID: 36521520
The first answer was the technical answer to my question strictly speaking, but I appreciate the issues mentioned in the other answer too. Thanks!
0

Featured Post

Ready for your healthcare security check-up?

In the past few years, healthcare organizations have become a prime target for advanced attacks. Does your organization have what it needs to defend itself? Schedule your healthcare security check-up today and download our free Healthcare Security Resource Kit today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question