x
all questions login
General DNS & Domains Dyn Email Update Clients Dyn Developer

Dear DynDNS community,

I want to enable DynDNS content filtering (Internet Guide Free Defence Plan) for everyone who accesses the 'net in my house, at a single point in the home network, without having to manually tweak it every day or two. Having trawled these forums, I got DynDNS working, but only in part.

I have a DynDNS account (free), with my host service running, a DSL WAN connection (ISP with dynamic IP allocation), a Linksys AM300 ADSL modem (firewall enabled) connected to a D-Link DI-624 wireless router which feeds the following computers:

  • Desktop (wired connection) running Windows XP (with DynDNS updater software installed) and Ubuntu eeePC. It is not always on.
  • Netbook (wireless connection) running Linux
  • Dell laptop (wireless connection) running Windows 7

I got DynDNS enabled and content filtering working between the modem and the desktop (no router) but when I introduce the DI-624 wireless router back into the network, the content filtering stops. I tried setting up DDNS on the DI-624 router but no luck.

I can't install DynDNS updater software on all the computers that come into the house, and I have a tech savvy teenager who would quickly get around it on his laptop. Besides, I don't want to install software, I want this to run from the router or the modem.

Suggestions?

more ▼

asked Mar 01 at 08:45 AM

ahalin\'s gravatar image

ahalin
1 1 1 1

10|600 characters needed characters left

3 answers:

Are all your clients connected to the D-Link? If so you just have to configure it with the Internet Guide DNS servers (in the WAN settings page).

As for outbound port blocking, I'm not sure that the D-Link supports it in that way (I can't see any sign that it does). You might need a router that supports DD-WRT firmware to allow you complete enough control (and you'd need one that supports OptWare to allow you to install a proxy server).


Be aware that if you do that (block all outbound traffic and force the use of a proxy) it is simply slightly challenging to bypass Internet Guide, instead of very easy. It is very, very, difficult to allow people access to the Internet and control what they can access. Entire industries are based around solving this problem, and even they can't provide a 100% solution. If your teenager wants to bypass the restrictions you put in place they'll be able to do so unless your technical skills are much greater than theirs, and you're willing to put more time and effort in than they are.

For example, if HTTPS is allowed out then you can use an SSL based VPN service (of which there are many commercial offerings and quite a few free ones) to connect through the proxy to gain unfiltered access. I use this approach all the time, though in my case it is because I don't trust the free Internet provisions at hotels, coffee shops etc.

more ▼

answered Mar 03 at 07:35 AM

Cry Havok\'s gravatar image

Cry Havok ♦
52.2k 13 26 222

10|600 characters needed characters left

You need to ensure that whatever is allocating the DHCP leases is including only the Internet Guide DNS servers, and not any other DNS servers. What device is allocating DHCP leases (presumably the D-Link)?

Note that unless you block all outbound connections and force everything through a proxy it's trivial to bypass a service like Internet Guide. At the very least you need to block port 53 (TCP and UDP) to everything that isn't the Internet Guide DNS servers.

more ▼

answered Mar 01 at 05:16 PM

Cry Havok\'s gravatar image

Cry Havok ♦
52.2k 13 26 222

10|600 characters needed characters left

Hi, thanks for responding!

It appears both the router and the modem are issuing DHCP leases:

  • DI-624: "The DI-624 can be setup as a DHCP Server to distribute IP addresses to the LAN network. DHCP Server: Enabled

    Starting IP Address 192 . 168 . 0 .100 Ending IP Address 192 . 168 . 0 . 199"

  • AM300: "Local DHCP Server: Enabled"

Port blocking is new to me. If I do that and enable the Dynamic DNS feature (server address http://www.DynDns.com with my Host Name, user name, password, etc) will that do it? I can't see anywhere on the DDNS settings page to put the Internet Guide DNS servers (four sets of numbers like OpenDNS's 208.67.222.222???) I can see a place for Primary and Secondary DNS Addresses in the WAN settings, Dynamic IP page.

more ▼

answered Mar 02 at 11:20 AM

ahalin\'s gravatar image

ahalin
1 1 1 1

10|600 characters needed characters left
Your answer
osqa.question.ask.tags.preview.show

© 1998-2012  Dynamic Network Services Inc.  -  Legal Notices  -  Privacy Policy  -  Contacts     

Powered by AnswerHub - Enterprise Social Q&A