Blocking Users From Overriding Other (Alternative) DNS Server(s)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Blocking Users From Overriding Other (Alternative) DNS Server(s)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Blocking Users From Overriding Other (Alternative) DNS Server(s)
Blocking Users From Overriding Other (Alternative) DNS Server(s)
2014-06-12 21:18:10 - last edited 2021-08-21 04:20:03
Region : UnitedStates

Model : TL-ER6120

Hardware Version : V1

Firmware Version : 1.0.6 Build 20131129 Rel.49461

ISP : ISP


I have a Question And Urgently Need Your Help!

I have The Router "TL-ER6120" Working Well, but I have some complications and need your suggestions and recommendations

I'm Using "OpenDNS.com" Service and Have set The OpenDNS addresses In my router wan interface to block and filter categorized sites which is provided by OpenDNS Service... It's working perfectly does it's best (Blocks and filters many sites which is listed in OpenDNS Web-filter Resource)
Now my problem Is:
After the blocking and filtering, my users managed to change the computer DNS servers to other DNS servers and they're overriding my OpenDNS Addresses which I set them in my router.
Now My Question:
Ho Can I Block Other DNS Servers except mine In the Router (That users couldn't use other DNS Servers, Addresses)

Thank You Very Much In Advanced!
  0      
  0      
#1
Options
1 Reply
Re:Blocking Users From Overriding Other (Alternative) DNS Server(s)
2014-10-07 14:19:18 - last edited 2021-08-21 04:20:03
I may be able to help you with this. I would use an access list under firewall.

First setup an access list to allow access to OpenDNS IP address. Then create an access rule to block all DNS access. This should only allow outside access to the DNS server you have granted access to which is OpenDNS. You need to make sure the OpenDNS allow access list has priority or is a lower number than the block all other DNS. Access rules are processed by order so when the allow is hit first the block all is never looked at.
  0  
  0  
#2
Options