Force DNS Exceptions

General discussion about Gargoyle, OpenWrt or anything else even remotely related to the project

Moderator: Moderators

Post Reply
Trailblazer
Posts: 113
Joined: Wed Mar 09, 2011 3:12 am

Force DNS Exceptions

Post by Trailblazer »

Hi Guys,
I would like to force everyone on the network to use the OpenDNS servers except for a few clients.

So I'll use 'Force Clients to use Router DNS Servers'. That works great and it's perfect for my purpose.

How do I allow just a few clients to use their own DNS servers (like me, for one)? I have added my IP and the DNS servers in the whitelist area of Exceptions, but the logic really isn't right and I didn't expect it to work there anyway.

Thanks!
Netgear WNDR3700V2 Gargoyle 1.10.0
TP-LINK Archer C7 v4 Gargoyle 1.12

User avatar
DoesItMatter
Moderator
Posts: 1373
Joined: Thu May 21, 2009 3:56 pm

Re: Force DNS Exceptions

Post by DoesItMatter »

Change the DHCP range to be something like

192.168.1.51 -> 192.168.1.250

Then put the exception clients as Static IP's in the
192.168.1.11 -> 192.168.1.50 range.

BUT

Those Static IP's won't have quota tracking either.

Kind of a Catch-22 on that setup.
:twisted: Soylent Green Is People! :twisted:
2x Asus RT-N16 = Asus 3.0.0.4.374.43 Merlin
2x Buffalo WZR-HP-G300NH V1 A0D0 = Gargoyle 1.9.x / LEDE 17.01.x
2x Engenius - ESR900 Stock 1.4.0 / OpenWRT Trunk 49400

z21
Posts: 7
Joined: Mon Jun 06, 2011 8:46 pm

Re: Force DNS Exceptions

Post by z21 »

I did it this way:
On the Connection> Basic page leave "Alternate DNS" as "Allow clients to use alternate DNS servers", and enter the OpenDNS servers as the Custom DNS servers.

On the Firewall>Restrictions page add a new restriction for all hosts except the ones you want to allow external DNS. Set it to Remote Ports Block Only 53. This won't block clients from the router DNS, which will be using OpenDNS, but will prevent connecting to alternate DNS.

Trailblazer
Posts: 113
Joined: Wed Mar 09, 2011 3:12 am

Re: Force DNS Exceptions

Post by Trailblazer »

Genius! Thanks!
Netgear WNDR3700V2 Gargoyle 1.10.0
TP-LINK Archer C7 v4 Gargoyle 1.12

Trailblazer
Posts: 113
Joined: Wed Mar 09, 2011 3:12 am

Re: Force DNS Exceptions

Post by Trailblazer »

For those who might be interested, as Z21 states, this stops DNS access for clients with their own DNS servers defined in their IP stack.

On their machine, they appear to not be on the internet as all web addresses fail (that aren't using IP addresses).

For the machines that I want to use their own DNS servers (defined in their respective IP stacks), it works perfectly.

Thanks again, z21!
Netgear WNDR3700V2 Gargoyle 1.10.0
TP-LINK Archer C7 v4 Gargoyle 1.12

tunaleya
Posts: 1
Joined: Mon Jul 18, 2011 6:18 am

Re: Force DNS Exceptions

Post by tunaleya »

How do i get my primary and secondary dns numbers? im trying to set up a router and when im doing the installation it asks for the dns primary and secondary. I went to network connections and went to the dns settings and its blocked out unless u click use new dns settings and then u can type ur own. What the hell do i do im getting real frustrated.
________________________________
yahoo keyword tool ~ overture ~ traffic estimator ~ adwords traffic estimator

Post Reply