Stopping Open DNS - FireBrick 105

From AAISP Support Site
The printable version is no longer supported and may have rendering errors. Please update your browser bookmarks and please use the default browser print function instead.

105-small.gif

FireBrick 105

FireBrick-icons.png

In a factory state the Filters on a FireBrick 105 will not allow DNS to the FireBrick from the WAN - the default state is to block incoming traffic, but to allow outgoing traffic. However, in some cases, customers disable the firewall by adding a rule that allows all traffic in. In this case, a new rule is needed to block DNS to the FireBrick.

Instructions

Create a Firewall filter to block port 53, from the WAN to the FireBrick, and make sure it's before any other rule that may allow this traffic in:

Name: BlockOpenDNS
Source: WAN
Target: FireBrick (The name of your FireBrick)
Action: Drop
Target ports: 53
Protocol: UDP


FireBrick-OpenDNS-Rule.png