Click here to get back home

How to disallow name resolution for external address?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
How to disallow name resolution for external address? kevin via WinServerKB.com 09-16-2005
Posted by kevin via WinServerKB.com on September 16, 2005, 3:02 am
Please log in for more thread options
Hi,

I have a PDC with DNS in it which only points to itself for name resolution.
This PDC is in Green zone and I disallowed all traffic from Green zone to Red
zone of the firewall for internet access, but only opened port 53 for DNS.
Is there any way to block name resolution for external address and only allow
name resolution for internal address?

Thanks.


--
Message posted via http://www.winserverkb.com


Posted by Miha Pihler [MVP] on September 16, 2005, 9:49 am
Please log in for more thread options
Hi,

If I understand you question, you would like to disallow any name resolution
outside your internal domain.

If this is so you have few options:
a) close UDP port 53 -- this will prevent any queries
b) make sure you don't have any forwarders set on your DNS servers (right
click on DNS server and click on Forwarders tab)
c) remove Root Hints from DNS servers (right click on DNS server and click
on Root Hints tab)

Most useful would be option a. Even if you do b. and c. users could still do
e.g.:

nslookup www.microsoft.com 193.2.1.66

where 193.2.1.66 is external DNS server.

I hope this helps,

--
Mike
Microsoft MVP - Windows Security

> Hi,
>
> I have a PDC with DNS in it which only points to itself for name
> resolution.
> This PDC is in Green zone and I disallowed all traffic from Green zone to
> Red
> zone of the firewall for internet access, but only opened port 53 for DNS.
> Is there any way to block name resolution for external address and only
> allow
> name resolution for internal address?
>
> Thanks.
>
>
> --
> Message posted via http://www.winserverkb.com




Posted by kevin via WinServerKB.com on September 21, 2005, 8:36 am
Please log in for more thread options
Hi,

Thanks for the reply. I would like to resolve internal hosts, but would like
to disallow all internal hosts to resolve any name outside my internal domain
especially public IP. I have few SIP phone users which need port 53 to
resolve from ISP. There is no forwarders configured for the server. If I
remove Root Hints, will there be any effect on name resolution for internal
hosts?


Miha Pihler [MVP] wrote:
>Hi,
>
>If I understand you question, you would like to disallow any name resolution
>outside your internal domain.
>
>If this is so you have few options:
>a) close UDP port 53 -- this will prevent any queries
>b) make sure you don't have any forwarders set on your DNS servers (right
>click on DNS server and click on Forwarders tab)
>c) remove Root Hints from DNS servers (right click on DNS server and click
>on Root Hints tab)
>
>Most useful would be option a. Even if you do b. and c. users could still do
>e.g.:
>
>nslookup www.microsoft.com 193.2.1.66
>
>where 193.2.1.66 is external DNS server.
>
>I hope this helps,
>
>> Hi,
>>
>[quoted text clipped - 8 lines]
>>
>> Thanks.


--
Message posted via http://www.winserverkb.com


Posted by Miha Pihler [MVP] on September 21, 2005, 10:01 pm
Please log in for more thread options
Hi,

You have few options.

Could you allow external DNS resolution just for IP addresses used by the
SIP phones and block for all other clients and servers?

You could block on firewall UDP port 53 just for your Active Directory DNS
server. This will prevent this server from resolving external hosts.

Another option would be to remove Root Hints. Personally, I would go with
first or second option. If you don't then users could still do e.g.

nslookup www.cnn.com 193.2.1.66

where 193.2.1.66 is IP address of external DNS server...

--
Mike
Microsoft MVP - Windows Security

> Hi,
>
> Thanks for the reply. I would like to resolve internal hosts, but would
> like
> to disallow all internal hosts to resolve any name outside my internal
> domain
> especially public IP. I have few SIP phone users which need port 53 to
> resolve from ISP. There is no forwarders configured for the server. If I
> remove Root Hints, will there be any effect on name resolution for
> internal
> hosts?
>
>
> Miha Pihler [MVP] wrote:
>>Hi,
>>
>>If I understand you question, you would like to disallow any name
>>resolution
>>outside your internal domain.
>>
>>If this is so you have few options:
>>a) close UDP port 53 -- this will prevent any queries
>>b) make sure you don't have any forwarders set on your DNS servers (right
>>click on DNS server and click on Forwarders tab)
>>c) remove Root Hints from DNS servers (right click on DNS server and click
>>on Root Hints tab)
>>
>>Most useful would be option a. Even if you do b. and c. users could still
>>do
>>e.g.:
>>
>>nslookup www.microsoft.com 193.2.1.66
>>
>>where 193.2.1.66 is external DNS server.
>>
>>I hope this helps,
>>
>>> Hi,
>>>
>>[quoted text clipped - 8 lines]
>>>
>>> Thanks.
>
>
> --
> Message posted via http://www.winserverkb.com




Posted by kevin via WinServerKB.com on September 22, 2005, 1:43 am
Please log in for more thread options
Thanks. I already solved this by disallowing PDC to use port 53 to resolve
external address. Just by denying PDC to resolve, all clients will be
disallowed also and it is working.



Miha Pihler [MVP] wrote:
>Hi,
>
>You have few options.
>
>Could you allow external DNS resolution just for IP addresses used by the
>SIP phones and block for all other clients and servers?
>
>You could block on firewall UDP port 53 just for your Active Directory DNS
>server. This will prevent this server from resolving external hosts.
>
>Another option would be to remove Root Hints. Personally, I would go with
>first or second option. If you don't then users could still do e.g.
>
>nslookup www.cnn.com 193.2.1.66
>
>where 193.2.1.66 is IP address of external DNS server...
>
>> Hi,
>>
>[quoted text clipped - 36 lines]
>>>>
>>>> Thanks.


--
Message posted via http://www.winserverkb.com


Similar ThreadsPosted
GPO to disallow USB drives on workstations? August 7, 2007, 8:38 pm
Disallow File or Directory Copy October 15, 2007, 11:13 am
S/MIME Certificates from External CA July 13, 2005, 4:52 pm
Wireless Security - External CA Setup March 13, 2007, 2:19 pm
can I connect to an external server using a local account? February 20, 2008, 12:45 pm
Re: share/move NTFS external disk between two separate computers September 5, 2005, 9:09 pm
RDP - IP Address ACL February 9, 2007, 3:18 pm
disable ip address June 14, 2005, 3:17 pm
Locating a LAN IP Address November 2, 2005, 8:40 pm
my computers address January 15, 2006, 2:35 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap