• February 23, 2025, 04:49:57 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: DFL 860 - Force users to use the routeur DNS + Layer 7  (Read 6420 times)

EnZ0

  • Level 1 Member
  • *
  • Posts: 2
DFL 860 - Force users to use the routeur DNS + Layer 7
« on: February 06, 2013, 07:20:25 AM »

Hi all and sorry for my poor english in advance !

I have a DFL-860 but I still can not do a thing, and I need the help of professionnals that you are.

I do filtering via OpenDNS, which answer a lot of expectation of my institution. Also, the DFL DNS1 is configuring with the IP of OpenDNS.

My concern is that the network can change carefree address their DNS on their notebook, and then also pass filtering.

What rule do I put in place to force the use of the DFL DNS for all users of the network?

Another secondary question: The DFL can filter the level 7 (particularly useful for blocking torrent etc)?

Thank you for your help!

A poor french guy
Logged

lingnau

  • Level 2 Member
  • **
  • Posts: 53
    • www.lingnau.com.br
Re: DFL 860 - Force users to use the routeur DNS + Layer 7
« Reply #1 on: February 12, 2013, 11:36:53 AM »

You can simply create a rule to deny DNS traffic. I think the best thing would be to create a SAT/Allow rule to allow the network clients to use the firewall's IP as DNS.
Second thing, create a rule to deny DNS traffic.

It would look like this(Or in your case, LAN source instead of DMZ and you could use normal SAT instead of SAT_SLB):

(There's a detailed  manual somewhere on D-Link website about how to do DNS SAT.

The firewall has IDP/IPS, i think it can block p2p but I've never used that.(I'm almost sure it also needs a subscription on the DFL-800, not sure about the DFL-860) I usually do the old fashion:
Allow HTTP, HTTPS, FTP, SMTP/POP (And secure variations) and deny all the rest. That resolves the torrent issue and another half a dozen issues.
« Last Edit: February 13, 2013, 03:58:00 AM by lingnau »
Logged

EnZ0

  • Level 1 Member
  • *
  • Posts: 2
Re: DFL 860 - Force users to use the routeur DNS + Layer 7
« Reply #2 on: February 12, 2013, 07:04:29 PM »

Thanks lingnau!

I try this solution quickly!
Logged

lingnau

  • Level 2 Member
  • **
  • Posts: 53
    • www.lingnau.com.br
Re: DFL 860 - Force users to use the routeur DNS + Layer 7
« Reply #3 on: February 15, 2013, 10:24:17 AM »

Thanks lingnau!

I try this solution quickly!

And, did it work? Please post back.
Logged

chechito

  • Level 3 Member
  • ***
  • Posts: 193
Re: DFL 860 - Force users to use the routeur DNS + Layer 7
« Reply #4 on: March 07, 2013, 08:14:46 PM »

that metodology its right i was using it since 2007
Logged