Community discussions

MikroTik App
 
kapone91
just joined
Topic Author
Posts: 15
Joined: Thu May 31, 2012 4:43 pm

Mikrotik as DNS Server

Tue Feb 18, 2014 12:25 pm

Hello ,

I have a question it is possible to use MK as an DNS server so that the WAN IP of the MK to be a DNS address.

For example :

My mk has the wan ip : 10.0.0.7 and it is at my office and i go home and i use ip 10.0.0.7 as DNS on my PC.
The thing that i want to accoplish its to restrict acces to all websites except few that i will allow usgin the DNS from the MK.

It is possible to do that ?

Thank you.
 
User avatar
karina
Member
Member
Posts: 462
Joined: Sat Feb 06, 2010 2:18 am
Location: Spain

Re: Mikrotik as DNS Server

Tue Feb 18, 2014 1:10 pm

yes, set up your preferred DNS servers in IP-DNS and tick allow remote requests, the router can then be used as a DNS relay where you can add your own static rules. Bear in mind you will need to add some firewall rules to direct all DNS requests to your own relay other wise people can simply specify there own DNS servers and bypass your relay. depending on the size of your network you may have to consider the power / storage capabilities of your router. Do not use any flash memory to store your cache as it will quickly die. If you have a public IP on the same router it is important to block external inbound requests or your DNS relay may be hijacked
 
kapone91
just joined
Topic Author
Posts: 15
Joined: Thu May 31, 2012 4:43 pm

Re: Mikrotik as DNS Server

Tue Feb 18, 2014 2:12 pm

I have tried something like this and some websites do not display or some of them display partial.
About what firewall rules do you talk can you give me and example please.
Thank you verry much.
 
SurferTim
Forum Guru
Forum Guru
Posts: 4636
Joined: Mon Jan 07, 2008 10:31 pm
Location: Miramar Beach, Florida

Re: Mikrotik as DNS Server

Tue Feb 18, 2014 2:54 pm

Wouldn't that be best accomplished by a transparent proxy instead of dns?

But even with that, you will get "partial" web pages in some cases where the allowed page has frames that are from a denied website.