MSFN Forum: Editing DSN lookups - MSFN Forum

Jump to content



Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Editing DSN lookups Rate Topic: -----

#1 User is offline   1boredguy 

  • Member
  • PipPip
  • Group: Members
  • Posts: 124
  • Joined: 28-August 04

Posted 12 May 2006 - 09:44 AM

Hello,

I need help. I want to disable gmail chat in a network, under a DNS server. I found these directions on the gmail help center, but I'm clueless of DNS server editing. How/where do I block DNS lookups?


"I am a network administrator, and need to disable Gmail's chat features on my network.
We understand that it's sometimes necessary to disable instant messaging services on a network. If you need to prevent Gmail users on your network from chatting, we suggest blocking DNS lookups to chatenabled.mail.google.com, by returning 127.0.0.1."


Any replies are appreciated!

This post has been edited by 1boredguy: 12 May 2006 - 09:45 AM



#2 User is offline   Gouki 

  • MSFN Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,168
  • Joined: 19-March 05

Posted 12 May 2006 - 10:06 AM

I think you need a 'static' entry on the Forward Lookup Zone so that the domain name ( chatenabled.mail.google.com ) gets resolved to 127.0.0.1.

#3 User is offline   1boredguy 

  • Member
  • PipPip
  • Group: Members
  • Posts: 124
  • Joined: 28-August 04

Posted 12 May 2006 - 10:23 AM

View PostGouki, on May 12 2006, 11:06 AM, said:

I think you need a 'static' entry on the Forward Lookup Zone so that the domain name ( chatenabled.mail.google.com ) gets resolved to 127.0.0.1.




I created a new Zone. Does it matter if it's primary or active directory-integrated?

I just left the zone blank. It seems to work just like that, the chat feature doesn't load.

#4 User is offline   Gouki 

  • MSFN Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,168
  • Joined: 19-March 05

Posted 12 May 2006 - 10:26 AM

Well, if it worked, great. I suggest Active Directory Integrated Zone. If you have the DNS server also as a DC, do it.

#5 User is offline   1boredguy 

  • Member
  • PipPip
  • Group: Members
  • Posts: 124
  • Joined: 28-August 04

Posted 12 May 2006 - 10:33 AM

View PostGouki, on May 12 2006, 11:26 AM, said:

Well, if it worked, great. I suggest Active Directory Integrated Zone. If you have the DNS server also as a DC, do it.



Thanks, very cool! If I want to return 127.0.0.1, then where do I do that?

If I get the "properties" of the zone, I see the tabs: General, State of Authority, Name Servers, WINS, Zone Transfers.

#6 User is offline   Gouki 

  • MSFN Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,168
  • Joined: 19-March 05

Posted 12 May 2006 - 10:34 AM

Create a new A record.

#7 User is offline   RJARRRPCGP 

  • MSFN Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,154
  • Joined: 13-April 05

Posted 13 May 2006 - 05:42 PM

View Post1boredguy, on May 12 2006, 11:44 AM, said:

Hello,

I need help. I want to disable gmail chat in a network, under a DNS server. I found these directions on the gmail help center, but I'm clueless of DNS server editing. How/where do I block DNS lookups?


"I am a network administrator, and need to disable Gmail's chat features on my network.
We understand that it's sometimes necessary to disable instant messaging services on a network. If you need to prevent Gmail users on your network from chatting, we suggest blocking DNS lookups to chatenabled.mail.google.com, by returning 127.0.0.1."


Any replies are appreciated!


I dunno about that, because if people know the IP address, then they can get around that!!

#8 User is offline   Gouki 

  • MSFN Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,168
  • Joined: 19-March 05

Posted 13 May 2006 - 06:06 PM

He can still add a new record to the Reverse Lookup Zone. That should get that problem fixed.

#9 User is offline   cluberti 

  • Gustatus similis pullus
  • Group: Supervisor
  • Posts: 11,001
  • Joined: 09-September 01
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 14 May 2006 - 10:28 AM

Ultimately, the only "sure-fire" way to block traffic anywhere is to use a proxy and funnel all traffic through it. DNS bloking will work for DNS names, but someone connecting to the IP address will bypass. However, if you don't have a proxy in place, the DNS blocking should work for most users, at least for a good while.

I'd still ultimately suggest a proxy to do things like this, but the DNS workaround will work.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2011 msfn.org
Privacy Policy