ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Web filtering for SMB

    IT Discussion
    9
    17
    899
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • dbeatoD
      dbeato
      last edited by

      I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

      black3dynamiteB scottalanmillerS 2 Replies Last reply Reply Quote 0
      • T
        thecreaitvone91
        last edited by thecreaitvone91

        Back in My SMB days I used NxFilter. You point your clients DNS to it (I did it using DHCP) and you can still use it if you have a domain, I just setup Zone Transfers from the AD DNS to Nxfilter, I had them setup in a failover pair. Does AD authentication for Group Lists of allowed/block sites, reporting etc. You'd normally block client devices from using Port 53 so they couldn't do their own lookups on your firewall.

        https://nxfilter.org/p3/

        DashrenderD 1 Reply Last reply Reply Quote 0
        • DashrenderD
          Dashrender @thecreaitvone91
          last edited by

          @thecreaitvone91 said in Web filtering for SMB:

          Back in My SMB days I used NxFilter. You point your clients DNS to it (I did it using DHCP) and you can still use it if you have a domain, I just setup Zone Transfers from the AD DNS to Nxfilter, I had them setup in a failover pair. Does AD authentication for Group Lists of allowed/block sites, reporting etc. You'd normally block client devices from using Port 53 so they couldn't do their own lookups on your firewall.

          https://nxfilter.org/p3/

          A zone transfer instead of just making the NXfilter the upstream DNS for AD's DNS?

          T 1 Reply Last reply Reply Quote 0
          • T
            thecreaitvone91 @Dashrender
            last edited by

            @Dashrender said in Web filtering for SMB:

            @thecreaitvone91 said in Web filtering for SMB:

            Back in My SMB days I used NxFilter. You point your clients DNS to it (I did it using DHCP) and you can still use it if you have a domain, I just setup Zone Transfers from the AD DNS to Nxfilter, I had them setup in a failover pair. Does AD authentication for Group Lists of allowed/block sites, reporting etc. You'd normally block client devices from using Port 53 so they couldn't do their own lookups on your firewall.

            https://nxfilter.org/p3/

            A zone transfer instead of just making the NXfilter the upstream DNS for AD's DNS?

            You couldn't do Groups or custom filters or reporting if you did it that way as all requests would be coming from the DC itself.

            1 Reply Last reply Reply Quote 0
            • black3dynamiteB
              black3dynamite @dbeato
              last edited by

              @dbeato said in Web filtering for SMB:

              I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

              Wouldn’t you just deny at the firewall from using any dns except for pi-hole?

              DustinB3403D JaredBuschJ 2 Replies Last reply Reply Quote 0
              • DustinB3403D
                DustinB3403 @black3dynamite
                last edited by

                @black3dynamite said in Web filtering for SMB:

                @dbeato said in Web filtering for SMB:

                I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

                Wouldn’t you just deny at the firewall from using any dns except for pi-hole?

                That's what I'd do.

                1 Reply Last reply Reply Quote 0
                • JaredBuschJ
                  JaredBusch @black3dynamite
                  last edited by

                  @black3dynamite said in Web filtering for SMB:

                  @dbeato said in Web filtering for SMB:

                  I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

                  Wouldn’t you just deny at the firewall from using any dns except for pi-hole?

                  This will only work for another year or so. Most browsers are going to default to DNS over HTTPS soon.

                  black3dynamiteB DashrenderD 2 Replies Last reply Reply Quote 0
                  • black3dynamiteB
                    black3dynamite @JaredBusch
                    last edited by

                    @JaredBusch said in Web filtering for SMB:

                    @black3dynamite said in Web filtering for SMB:

                    @dbeato said in Web filtering for SMB:

                    I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

                    Wouldn’t you just deny at the firewall from using any dns except for pi-hole?

                    This will only work for another year or so. Most browsers are going to default to DNS over HTTPS soon.

                    Yeah, I forgot about that.

                    1 Reply Last reply Reply Quote 0
                    • DashrenderD
                      Dashrender @JaredBusch
                      last edited by Dashrender

                      @JaredBusch said in Web filtering for SMB:

                      @black3dynamite said in Web filtering for SMB:

                      @dbeato said in Web filtering for SMB:

                      I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

                      Wouldn’t you just deny at the firewall from using any dns except for pi-hole?

                      This will only work for another year or so. Most browsers are going to default to DNS over HTTPS soon.

                      This is overridable. So for business it something you can overcome.
                      And MS is also working to update their DNS to be DNS over HTTPS... just need PI Hope to follow suit... then the browser will stick with the DHCP provided DNS.

                      JaredBuschJ 1 Reply Last reply Reply Quote 0
                      • JaredBuschJ
                        JaredBusch @Dashrender
                        last edited by

                        @Dashrender said in Web filtering for SMB:

                        @JaredBusch said in Web filtering for SMB:

                        @black3dynamite said in Web filtering for SMB:

                        @dbeato said in Web filtering for SMB:

                        I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

                        Wouldn’t you just deny at the firewall from using any dns except for pi-hole?

                        This will only work for another year or so. Most browsers are going to default to DNS over HTTPS soon.

                        This is over rideable. So for business it something you can’t overcome.
                        And MS is also working to update their DNS to be DNS over HTTPS... just need PI Hope to follow suit... then the browser will stick with the DHCP provided DNS.

                        Can you edit that to English?

                        1 Reply Last reply Reply Quote 1
                        • scottalanmillerS
                          scottalanmiller @AdamF
                          last edited by

                          @fuznutz04 said in Web filtering for SMB:

                          @DustinB3403 said in Web filtering for SMB:

                          Are you looking to block content, like online gambling, porn etc? PiHole does an amazing job out of the gate and makes it pretty easy to do this if you want something quick and simple to setup and maintain.

                          I use Pi-Hole at my house. Good idea. I'm looking to block accidental stuff. Want to do what I can to keep malware, etc out as much as possible.

                          Pi-Hole + CloudFlare DNS goes a long way. And free.

                          1 Reply Last reply Reply Quote 2
                          • scottalanmillerS
                            scottalanmiller @dbeato
                            last edited by

                            @dbeato said in Web filtering for SMB:

                            I have continued to use Untangle, Pi-Hole and Yes NGFW as well. So it depends what you want to use, if DNS you know people can circumvent them outright but it is all up to you.

                            He said his goal was accidents. DNS filtering is perfect for accidents.

                            1 Reply Last reply Reply Quote 3
                            • 1 / 1
                            • First post
                              Last post