Solved

How best to block all IP traffic to the new .XXX domains

Posted on 2011-09-09
7
1,246 Views
Last Modified: 2012-05-12
In a Microsoft Windows Server 2003 AD network, is it possible to use Microsoft DNS to block access to all subdomains of the new .XXX TLD? The firewall router is not capable of URL filtering.
0
Comment
Question by:askrabbit
7 Comments
 
LVL 9

Accepted Solution

by:
Chev_PCN earned 400 total points
ID: 36509463
You can't use DNS to actively block. You CAN stop it from resolving through.
It's as simple as creating a zone for XXX and leaving it empty.
What this does, is it makes your DNS organisation authoritative for that domain (i.e. the only one that can do resolution), so if a client asks for a XXX address, it will come back blank.
Unfortunately if a client uses the IP address, they can still access the site.
You would be best putting in a proxy of some sort.  Free, powerful & easy to administer is squid.
0
 
LVL 14

Expert Comment

by:setasoujiro
ID: 36509869
another thing to consider is that people could still use a public dns , instead of your own.
Unless you blocked their ability to change their dns settings
0
 
LVL 26

Expert Comment

by:Soulja
ID: 36510150
What type of firewall/ router do you have?
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 2

Author Comment

by:askrabbit
ID: 36510153
Chev_PCN, we did in fact try your suggestion already, but without success. However, I have realised that I was making a mistake when testing by using a fictitious xxx domain/host. I discovered that porn.xxx and sex.xxx are "Safe for Business" placeholder sites. When I used these for testing, I found that the disruption to DNS resolution works fine. Thank you! I understand your point about direct access via IP address. Also, there are plenty of porn sites on .com, etc which would still be accessible. Still, the client asked me a specific question...

Thank you for your comment about proxies. This is also under consideration.

setasoujiro, Fair point, although most users are not local admins and so would not be able to change any workstation IP settings.
0
 
LVL 14

Assisted Solution

by:setasoujiro
setasoujiro earned 100 total points
ID: 36510271
yeah but they could also just use an online proxy if they really have the pornurge :)
and if this is such a concern to your company i would strongly advice to purchase a webblocking capable device , I can safely say that watchguard offers a strong webblocker/application blocker combined with firewall/Antispam etc,  and is not too expensive either
0
 
LVL 2

Author Comment

by:askrabbit
ID: 36521507
Thank you to both of you for your comments. I have certainly told the company that just focussing on .XXX does not mean no porn... ;-)
0
 
LVL 2

Author Closing Comment

by:askrabbit
ID: 36521520
The first answer was the technical answer to my question strictly speaking, but I appreciate the issues mentioned in the other answer too. Thanks!
0

Featured Post

Active Directory Webinar

We all know we need to protect and secure our privileges, but where to start? Join Experts Exchange and ManageEngine on Tuesday, April 11, 2017 10:00 AM PDT to learn how to track and secure privileged users in Active Directory.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
OSPF - Convergence & Downtime 9 37
Auto-launch VPN via Wifi 7 49
Remote access problem to camera controller 9 37
can't ssh to external IP 9 23
Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

832 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question