+ Post New Thread
Results 1 to 14 of 14
Networks Thread, DNS port in Technical; Hi I am using the opendns.com service. I'm trying to make a rule(s) in my router firewall so that someone ...
  1. #1

    Join Date
    Mar 2008
    Posts
    81
    Thank Post
    8
    Thanked 0 Times in 0 Posts
    Rep Power
    0

    DNS port

    Hi

    I am using the opendns.com service.

    I'm trying to make a rule(s) in my router firewall so that someone can't manually change the dns servers on their pc using this method OpenDNS Community > Forums > IF A USER USE MANUEL DNS, HE PASSES ALL BLOCKING CATS

    To see if I am working with the right port I blocked all outbound traffic through port 53 on my router but I can still access websites

    What am I doing wrong? I thought port 53 was the DNS port?

    TIA

  2. #2

    Michael's Avatar
    Join Date
    Dec 2005
    Location
    Birmingham
    Posts
    6,190
    Thank Post
    151
    Thanked 946 Times in 737 Posts
    Rep Power
    197
    DNS is port 53 TCP/UDP

  3. #3

    Join Date
    Mar 2008
    Posts
    81
    Thank Post
    8
    Thanked 0 Times in 0 Posts
    Rep Power
    0
    I have port 53 TCP/UDP blocked but I can still surf the internet

  4. #4
    Jay
    Jay is offline

    Join Date
    Mar 2008
    Location
    Autocratic theocracy of Norfolk
    Posts
    71
    Thank Post
    3
    Thanked 4 Times in 4 Posts
    Rep Power
    8

    Post DNS

    If you use an HTTP(S) proxy then the proxy handles name resolution for you. Also your machine might be using a local DNS server with forwarding configured. In either case if those machines are permitted outbound 53 UDP access then you would still be able to resolve names to IP's when browsing.

    Don't know if that helps any.

  5. #5

    Join Date
    Aug 2005
    Location
    London
    Posts
    3,110
    Blog Entries
    2
    Thank Post
    110
    Thanked 511 Times in 443 Posts
    Rep Power
    114
    not sure I understand what you've done.

    I'm assuming you've got a network with workstations configured to point to a server as the DNS server and then that is forwarding requests to OpenDNS? What you're trying to do is stop users connecting directly to a DNS server by blocking port 53 outbound on your router? Presumably you're allowing port 53 for requests from the server?

    If this is the case then it's not going to work - when you type (eg) EduGeek.net on the workstation, it passes that to your server DNS. It doesn't know the answer and so it goes out through your router to OpenDNS (or whoever).

    You could stop your internal DNS from forwarding but then you won't be able to do any web browsing from any machine.

    You can set forwarding so that it forwards for a whitelist of domains and drops everything else but that's quite a hard way to do web filtering.

  6. #6

    Join Date
    Mar 2008
    Posts
    81
    Thank Post
    8
    Thanked 0 Times in 0 Posts
    Rep Power
    0
    Hi

    I will try and explain better this time.

    There are 10 pc's which are connected to an ADSL router via a 12 port switch. All 10 pc's are set to get ip & dns servers automatically.

    In the router the DNS servers are set to the opendns.com servers.

    I noticed the other day that to get past this someone had manually set the DNS servers on a couple of the pc's to something else to bypass the opendns filtering.

    This is what I want to stop.

  7. #7


    Join Date
    Feb 2007
    Location
    Northamptonshire
    Posts
    4,411
    Thank Post
    322
    Thanked 715 Times in 644 Posts
    Rep Power
    199
    Which router?

  8. #8

    Join Date
    Mar 2008
    Posts
    81
    Thank Post
    8
    Thanked 0 Times in 0 Posts
    Rep Power
    0
    Netgear something. I will get the exact model number tomorrow.

  9. #9


    Join Date
    Feb 2007
    Location
    Northamptonshire
    Posts
    4,411
    Thank Post
    322
    Thanked 715 Times in 644 Posts
    Rep Power
    199
    On my netgear I did the following and it works perfectly.

    Block Services
    TCP/UDP 53-53 all IPs
    Enable the "Always" as Shedule.

    So, now, I can query my router for DNS which gets its answers from upstream DNS provider BUT I cannot from my laptop directly contact any dns servers outside of the network because the router won't allow it.

    I believe this is what you're trying to achieve?

  10. #10

    Join Date
    Mar 2008
    Posts
    81
    Thank Post
    8
    Thanked 0 Times in 0 Posts
    Rep Power
    0
    Just to confirm these pc's are not connected to a server. They just take there ip & dns settings from the router (apart from when people are manually changing the dns settings on indicidual pc's to bypass the opendns servers)!

    What I can't understand is that I have outgoing traffic to port 53 blocked in the router firewall, yet I can still surf the internet

  11. #11


    Join Date
    Feb 2007
    Location
    Northamptonshire
    Posts
    4,411
    Thank Post
    322
    Thanked 715 Times in 644 Posts
    Rep Power
    199
    Forget the server, that's not relevant.

    If your PC is using the router IP for DNS then of course you can still browse the net, but if you are using 'external' DNS servers then no it shouldn't work which suggests your firewall rule is wrong.

    Perhaps a screenshot of the rule would be useful as there is something wrong.

  12. #12

    Join Date
    Mar 2008
    Posts
    81
    Thank Post
    8
    Thanked 0 Times in 0 Posts
    Rep Power
    0
    Sorry if I'm not explaining things very well

    I will post some screen shots when I get home but to confirm yes all the pc's are using the dns addresses from the router which are set to:-

    208.67.222.222
    208.67.220.220

  13. #13

    Join Date
    Mar 2008
    Posts
    81
    Thank Post
    8
    Thanked 0 Times in 0 Posts
    Rep Power
    0
    If you look at this example picture the outbound rule set on my router is



    ENABLE=YES
    SERVICE NAME=DNS(:53)
    ACTION=BLOCK ALWAYS
    LAN USERS=ANY
    WAN USERS=ANY
    LOG=ALWAYS

  14. #14

    Join Date
    Mar 2008
    Posts
    81
    Thank Post
    8
    Thanked 0 Times in 0 Posts
    Rep Power
    0
    I've got it working now but not with my netgear even though it has the latest firmware. On my router blocking the dns port doesn't stop dns traffic so I tried it with another model netgear I had and it works fine.

SHARE:
+ Post New Thread

Similar Threads

  1. Replies: 3
    Last Post: 19th February 2008, 11:13 PM
  2. USB Port tester
    By contink in forum Hardware
    Replies: 1
    Last Post: 10th September 2007, 01:02 PM
  3. 2 port external HD?
    By Samson in forum Hardware
    Replies: 11
    Last Post: 17th July 2007, 01:40 PM
  4. Port Usage
    By Craig_W in forum Networks
    Replies: 4
    Last Post: 14th May 2007, 08:11 AM
  5. 5 port switch
    By chrbb in forum Networks
    Replies: 4
    Last Post: 10th July 2006, 02:08 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •