Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Anders_Jensen
New Contributor

Redirect all DNS requests to local server

Hi, i am running a closed network for exam purposes in a school. I have a DHCP-server that hands out ip-adresses along with the IP of my local DNS-server. I see more and more of the students having there own static DNS-servers (openDNS, GoogleDNS and so on), which means that they are not able to connect to my internal print-solution. Can a Fortigate somehow redirect all DNS requests to my own internal server, so I dont have to instruct the students in removing the static DNS and use mine every time we have exams? Regards Anders
11 REPLIES 11
ede_pfau
SuperUser
SuperUser

To put it in simple terms: your LAN - your rules. A DHCP network offers dynamic assignment of the gateway and the DNS both of which are essential. Your users are not debating over the gateway setting, are they? Same applies to the DNS. At home they would have no problems at all leaving the dynamic DNS assignment in place, if set up is correctly. DNS to external servers must be blocked. Tunneling over DNS is a reality, and IMHO in the context of exams it' s something you have to suppress. So you close 2 gaps with one setting.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Anders_Jensen
New Contributor

First of all, thank you for all your suggestions. Fantastic to see some enthusiastic people :) I think i' ll try rwpattersons solutions with virtual IPs. I know it isn' t perfect, but i can begin with Google and OpenDNS' s servers and then see how many others i have to add. Emnoc > I have already blocked all internet connection for the students on the special Exam network. It is only possible to reach my internal print-solution and an online dictionary for which have a static a-record in my DNS and a corresponding opening in the Fortigate firewall. Therefore all the student' s own static DNS' s is blocked by the firewall. As ede_pfau wrote DNS-tunneling is possible if the DNS-port is open and I of course want to prevent that. Many students have those static DNS' s from Google and OpenDNS because the ISPs here in Denmark is forced to block certain pages, such as The Pirate Bay, in their DNS-servers. Regards Anders
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors