Allow ISATAP and WPAD in OpenDNS Whitelist?
Posted on 2012-04-11
I have recently implemented OpenDNS web content filtering at all of my company's retail locations. I've chosen to use their Whitelist available with the Enterprise package to limit access. Choosing this method required us to compose a list not only of sites they will need to browse but sites necessary for all related technology to function and update.
In monitoring the blocked domains I have found a number of isatap.<domain> and wpad.<domain> entries. I have researched these but I have not yet found anything which can assure me that it will be safe to allow them. OpenDNS, naturally, uses their DNS servers to enforce the filtering so I need to be absolutely sure these will not allow users to bypass this.
This may be a silly question for you networking gurus, but I am not yet there and would really appreciate some help understanding this. Thanks!