Discussion in 'DNS Server' started by Bear, Oct 2, 2006.

  Bear

    Bear Guest


    Is there a simple way for me to redirect users that are attempting to use
    outside proxy servers to an internal site using the DNS capabilities of
    Windows Server 2003. For instance, if a user wants to access they could be redirected to http://mywebserver.mydomain

    We are experiencing this issue with our students using these web-accessable
    proxies to bypass our content filtering solution. Unfortunately I am part of
    a consortia that doesn't provide direct access to filtering lists.

    Any suggestions would be greatly appreciated.
    Bear, Oct 2, 2006
  steve_t

    steve_t Guest

    If you knew the URL for every site that the students are using, you could
    create an alias, or CNAME record, for each site. In your example, you would
    use as the alia and mywebserver.mydomain as the FQDN for the
    target host. The biggest problem you'll have with this solution is
    determining all of the sites you want to filter. There are probably other
    solutions as well, but I hope this helps a bit.

    steve_t, Oct 2, 2006
  steve_t

    steve_t Guest

    steve_t, Oct 2, 2006
  4. The only 100% sure way of doing this is to disable or block NAT to the
    clients and force the use of your own proxy server.
    Creating aliases and zones in DNS won't stop a determined user.

    Kevin D. Goodknecht Sr. [MVP], Oct 2, 2006
  Bear

    Bear Guest

    Thanks for the input. Would I have to create a new Zone, as wouldn't my
    domain name be appended to the end of the of the record, such as or am I mistaken?
    Bear, Oct 2, 2006
  steve_t

    steve_t Guest

    I don't think it will append your domain name, but I'm not sure - I don't
    have a system I can play with to test it out. However, as Kevin pointed out
    in his reply, this won't really stop a determined person. Inputting the IP
    address of the site bypasses DNS resolution completely, and it's very easy to
    get that information.

    steve_t, Oct 2, 2006
