• February 23, 2025, 02:09:17 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: I am trying to block port 53 and cannot find anything in router config  (Read 15850 times)

pctech4747

  • Level 1 Member
  • *
  • Posts: 10

I take it that this router does not support outgoing port blocking?  i tried to call support but they want my credit card. 

Anyone know? 

I have a router in a box, i think its a linksys wrt54g.  maybie i have to have 2 routers to accomplish this?

I want to block outgoing port 53 because i heard that is what people use to get around DNS servers that the router hands out via DHCP.  I want all clients to not be able to get around my dns policy restrictions using opendns.

Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: I am trying to block port 53 and cannot find anything in router config
« Reply #1 on: December 14, 2011, 10:17:48 AM »

You could try using Virtual Server options and select Deny ALL. However this is for Inbound only.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

fraggboy

  • Level 3 Member
  • ***
  • Posts: 182
Re: I am trying to block port 53 and cannot find anything in router config
« Reply #3 on: December 14, 2011, 12:55:28 PM »

I *think* this might be accomplished by using Access Control.

Go to Advanced -> Access Control.  Enable Access Control.

Then click Add policy.

Go through the wizard.

When you get to Add Machine, you can add all PC's at once.

Default is "Block some access".
Click "Apply Advanced Port Filters".
Give it a name, and keep the Dest IP address and End IP address default.  Just change the port to 53.
Then click Save.

That should work for you.  I can't test it myself due to me being at work.
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: I am trying to block port 53 and cannot find anything in router config
« Reply #4 on: December 14, 2011, 12:59:21 PM »

Good info, forgot about Block Some Access.


Let us know if that works.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

pctech4747

  • Level 1 Member
  • *
  • Posts: 10
Re: I am trying to block port 53 and cannot find anything in router config
« Reply #5 on: December 14, 2011, 02:42:23 PM »

I *think* this might be accomplished by using Access Control.

Go to Advanced -> Access Control.  Enable Access Control.

Then click Add policy.

Go through the wizard.

When you get to Add Machine, you can add all PC's at once.

Default is "Block some access".
Click "Apply Advanced Port Filters".
Give it a name, and keep the Dest IP address and End IP address default.  Just change the port to 53.
Then click Save.

That should work for you.  I can't test it myself due to me being at work.

you say just change port to 53.  well i did that on start and end on the ports for all protocols.  i tested on me and it would not even resolve google.  NOT WORKING even after checking that my network card is all on automatic dhcp.

« Last Edit: December 14, 2011, 02:44:37 PM by pctech4747 »
Logged

fraggboy

  • Level 3 Member
  • ***
  • Posts: 182
Re: I am trying to block port 53 and cannot find anything in router config
« Reply #6 on: December 14, 2011, 04:00:43 PM »

Hmm.. :(

I'd have to run some tests when I get home to figure out if there is another way.  Sorry about that.
Logged

pctech4747

  • Level 1 Member
  • *
  • Posts: 10
Re: I am trying to block port 53 and cannot find anything in router config
« Reply #7 on: December 15, 2011, 07:18:36 AM »

ok i bookmarked this thread.  I really would be happy to see if you can figure it out.  Your solution seems like it should work.   I know this router is for gamers, so who would want to block any outgoing ports.   Me cause i game, but also give out free internet to my upstairs roommates.  I want opendns to be forced to them and if they know how to change the dns servers on their computers, I want it to not work unless they set to Automatic DHCP and DNS in networking properties of their NIC card.

Logged

fraggboy

  • Level 3 Member
  • ***
  • Posts: 182
Re: I am trying to block port 53 and cannot find anything in router config
« Reply #8 on: December 15, 2011, 09:51:39 AM »

Sorry I took so long to respond.  Morning meetings (Plural). :(

So, I'm taking that you have enabled "DNS Relay" (Found on Basic -> Network Settings Page)?
(If might be greyed out if you have "Enable Advanced DNS Service" checked. (Found on Basic -> Internet -> Manual Configure).

If you do have DNS Relay enabled, then I'm thinking the only way would be to disable DNS Relay, use a LAN-side DNS server as a virtual server, and then set up the port block as described above.
Logged

pctech4747

  • Level 1 Member
  • *
  • Posts: 10
Re: I am trying to block port 53 and cannot find anything in router config
« Reply #9 on: December 15, 2011, 03:42:28 PM »

 i found dns relay, and wasnt checked, neither was adv dns,  checked dns relay, rebooted, flushed dns on client, still did not work, and also it made my remote support with teamviewer not work properly.  can you test your config to see if it works.  maybie i did it wrong.

p.s. i appreciate your input on this. 
Logged

fraggboy

  • Level 3 Member
  • ***
  • Posts: 182
Re: I am trying to block port 53 and cannot find anything in router config
« Reply #10 on: December 15, 2011, 04:35:41 PM »

Yes, I will check later on tonight. I have to run a few errands after work, but will check and see if the settings work on my end.  They are pretty cut-and-dry so I feel I might get the same results (But I will give it a shot).

If it doesn't work, then I think you might have to resort to running a LAN-based DNS server.
Logged

fraggboy

  • Level 3 Member
  • ***
  • Posts: 182
Re: I am trying to block port 53 and cannot find anything in router config
« Reply #11 on: December 15, 2011, 06:41:11 PM »

OK, I tested it out.. The router is only passing the DNS information to the LAN computers to use for inquiry.  Which in reality, makes sense now.  It's not a DNS server/router..  ;D

Here is my log entry when I try (And then it hit me): [INFO]   Thu Dec 15 18:33:10 2011   DNS relay ALG rejected packet from 192.168.0.100:64253 to 204.194.232.200:53  It's not pointing to the router.

So, what I said above *should* work.  I don't have a server to check it out unfortunately but create a DNS server on the LAN side and then block port 53 using Access Control.  Then, you will want to edit the primary/secondary DNS IP's pointing to your DNS server on page: Basic -> Internet -> Manual Configure.  It will be greyed out if the Advanced DNS service is enabled (Disable it).

« Last Edit: December 15, 2011, 06:44:02 PM by fraggboy »
Logged

pctech4747

  • Level 1 Member
  • *
  • Posts: 10
Re: I am trying to block port 53 and cannot find anything in router config
« Reply #12 on: December 16, 2011, 12:33:21 PM »

i dont have an extra pc to put up 24/7 as a dns server.  this is for home use.  i do have  a spare linksys wrt54g router, and a spare Syswan duolinks sw24 http://www.syswan.com/SW24_Overview.htm

would hooking up one of these do the task?
Logged

fraggboy

  • Level 3 Member
  • ***
  • Posts: 182
Re: I am trying to block port 53 and cannot find anything in router config
« Reply #13 on: December 16, 2011, 12:38:23 PM »

No.  You will need to set up a server.
Logged