Deny access to a DNS host for a subnet

Jean-François Guénet
Jean-François Guénet used Ask the Experts™
Hello is it possible to deny access to a A host in Windows 2016 DNS for a subnet

So for exemple i don't want that the subnet can know about the host OWA

So for exemple if ping OWAi don't want him to know the ip adress

The reason for this is that we have Cellphone and when they connected to the VPN email client don't work because they tried to reach OWA with the internal ip

So i want them to use the external public ip of OWA instead when connected to the VPN

Thanks for the help !
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
nociSoftware Engineer
Distinguished Expert 2018

Either create some firewall rule to block the (or better, reject ) the connections from there
or null route (black hole route...) the subnet you want to block.

Some DNS servers have their own access rules.
timgreen7077Exchange Engineer
Distinguished Expert 2018

VPN is basically your internal network so OWA should work just fine, but the native email client may be affected and not work, but OWA should still work. is that what you are experiencing?
Network Engineer
If you blocked access to the DNS server for your VPN clients, then ALL DNS will fail for them. You can't assign public DNS to them either, because then all name resolution to your internal network will be broken.

As I see things, in order to make this work at all, you need to modify the firewall to allow access to the OWA server, at the private IP address, while on the VPN. Can the VPN clients even hit OWA on the public IP?

A slightly different route, is to change internal DNS to point to the public IP for OWA, and to modify the firewall so that everything from the inside, including all inside networks and the VPN.
Justin YeungSenior Systems Engineer

for windows DNS, you are out of luck.

I do not know what is the purpose of this, however the work around is setup a standalone DNS (I assume you are in DMZ), may be 2 servers as the DNS servers for the subnet.

you can configure any record as you wish without breaking the production DNS. (a zone that only sits in the DMZ dns)
Jean-François GuénetNetwork Administrator


Ive done what kevinhsieh told.  So i create a NAT Loopback so internal client can access OWA with external ip address and my dns host OWA now point to the external ip address instead of private ip

Thanks !

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial