LCPSWolf Posted April 22, 2009 Posted April 22, 2009 Hey all, I'm trying to get opinions on using OpenDNS (OpenDNS | Providing A Safer And Faster Internet) to filter web content for K-12 schools. I've tested it in a small sample and it seems decent, so long as we can prevent users from changing DNS settings. Pros: Saves our district ~ $7,000 USD a year for filtering license Uses a category database that another pay-for product uses (I want to say it's the iGuard database that the iPrism uses, but I've looked at some many recently I could be wrong). Allows for black/white list URL's similar to our currently filtering (Fortinet) Cons: Generally untested Doesn't provide deep packet inspection and dynamic proxy blocking like other pay-for sources (DeepNines as an example) If anyone's using this, I'd love their take on it. We're converting from a Novell network to Microsoft and expect to use group policy to prevent changes to DNS - if anyone knows why that won't work, please give me a shout, too. (I'm new to GP but am learning quickly). Hope everyone's doing well. Thanks as always. Damian Bailey Lead Tech Louisa County Schools, VA, USA
Michael Posted April 22, 2009 Posted April 22, 2009 It's very good considering it's free. I use it just as my DNS at home. I don't use the available filtering options (which just requires you to create an account). It would be perfect if it was made impossible to enter numbers (IP addresses) into the address bar in Internet Explorer. This may be possible by creating a custom plugin, or something along those lines; however if it was, I would be surprised why it hasn't already been done.
LCPSWolf Posted April 22, 2009 Author Posted April 22, 2009 It's very good considering it's free. I use it just as my DNS at home. I don't use the available filtering options (which just requires you to create an account). It would be perfect if it was made impossible to enter numbers (IP addresses) into the address bar in Internet Explorer. This may be possible by creating a custom plugin, or something along those lines; however if it was, I would be surprised why it hasn't already been done. Galway: My boss will be excited that it will track the IP address used to log sites. We pay extra for a tracking software that we may also not need with that. ...now if it would just map with AD (not likely as it's outside our network, technically Michael: Just so I'm following you, OpenDNS will allow IP addresses into the address bar, but does it still block those IP's of sites that are in its blacklist or "bad" category lists? Or is entering IP address of sites a workaround to its filtering? (Seems like a large hole, but something good to know). I'll also change over my DNS settings here on my laptop and test it as well..but just curious if you've already done the same.
Michael Posted April 22, 2009 Posted April 22, 2009 This is the main problem with DNS filtering. DNS converts web addresses we as humans type into IP addresses and retrieves the website you've requested. Typing an IP address directly into Internet Explorer bypasses the need for DNS, so the page is retrieved automatically. So in theory, a pupil could work out the IP for an adult website and enter it within school. Open DNS wouldn't filter this and pupils would be required to have lists of IPs instead of web addresses. 1
LCPSWolf Posted April 22, 2009 Author Posted April 22, 2009 Michael, What a great point (and a polite explanation of DNS . I'll research a way to block this - it now makes sense some of the help documentation I've seen on our Fortigate box that has a wildcard mask for blocking IP addresses of this type. Awesome. I'll let you know what I come up with.
powdarrmonkey Posted April 22, 2009 Posted April 22, 2009 Pros: Saves our district ~ $7,000 USD a year for filtering license No, it doesn't. DNS filtering is all or nothing for a given domain (example.com), so you can't differentiate between example.com/goodstuff and example.com/badstuff. You still need an URL- or content-based filter in place.
matt40k Posted April 22, 2009 Posted April 22, 2009 Seems a bit.... well... how is it funded? Bit too good to be true.
LCPSWolf Posted April 22, 2009 Author Posted April 22, 2009 No, it doesn't. DNS filtering is all or nothing for a given domain (example.com), so you can't differentiate between example.com/goodstuff and example.com/badstuff. You still need an URL- or content-based filter in place. Good point. We typically are blocking total domains, but there may be cases we want to only block a portion....hmm. Have to wonder if that's worth it. Thanks.
powdarrmonkey Posted April 22, 2009 Posted April 22, 2009 Have to wonder if that's worth it. It's worth it as part of your arsenal, just don't throw out the gun cupboard for a mouse trap.
LCPSWolf Posted April 22, 2009 Author Posted April 22, 2009 (edited) I love that analogy! Going back to the not blocking by IP, I just changed by DNS settings on my laptop to OpenDNS servers (208.67.222.222 and 208.67.220.220) and attempted to browse to 208.69.32.130. (I'm running IE7, for what that's worth). It was blocked as a site not allowed on our network (gambling). I had not visited this site previously. Am I missing something or is this working better than expected? I just saw that OpenDNS uses St. Bernard's iGuard data for its category filtering. Edited April 22, 2009 by LCPSWolf updated filtering category source
m25man Posted April 22, 2009 Posted April 22, 2009 OpenDNS rocks and the reason it is disliked by many on this forum is because it make their expensive filtering systems look like the rip off they have become! Open DNS still filters IP addresses only. Yes, the lack of granular control can be an issue for some but in those sites we have worked around this with multiple gateways and configured proxies. What I like most about it is that as more people find ways to migrate to it and make it work for them the commercial products have to stop charging ridiculous rates for their services:D If you can save $000's of dollars this year when budgets are cut to the bone and your job is on the line why not. Hey, it's not going to cost you a penny to try it!
EduTech Posted April 22, 2009 Posted April 22, 2009 I use it at home, and yeah it's pretty good stuff! faster then waiting for virgin's DNS Records to update and best of all it's FREE well done to those guys
Michael Posted April 22, 2009 Posted April 22, 2009 OpenDNS had a huge cash injection put into it, as they have DNS servers strategically positioned over most parts of the world. Not only does this speed things up, it also adds redundancy too. Rumour has it also that their DNS servers speed up access, but I believe this to be false. However, another advantage to its service is they're using DNS to block the sources of Conflicker. Again this is all free and no doubt they'll introduce other services based around DNS. As for making money, they are in partnership with Yahoo and generate $20,000 a day from viewing/clicking on adverts. A typical example is if you mis-typed a URL you'll be redirected to their customised Yahoo search. It's as simple as that.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now