View difference between Paste ID: e7zJj51v and qYmyFAyK
SHOW: | | - or go back to the newest paste.
1
To restrict DHCP clients from connecting to the internet if they manually input DNS settings, you can configure your MikroTik router to enforce DNS settings through DHCP. This ensures that DNS configuration is obtained automatically from the DHCP server. Follow these steps using the WinBox interface:
2
3
Access WinBox:
4
5
Connect to your MikroTik router using the WinBox application.
6
Go to IP > DHCP Server:
7
8
In the left menu, navigate to IP and then click on DHCP Server.
9
Select Your DHCP Server:
10
11
Choose the DHCP server that is providing IP addresses to the clients.
12
Configure DNS Settings:
13
14
In the DHCP Server settings, there should be an option for "Use Peer DNS." Ensure this option is enabled. This option tells the DHCP server to provide DNS settings received from the ISP (Internet Service Provider) rather than static DNS settings.
15
Limit DNS Access:
16
17
To prevent clients from manually configuring DNS settings, you can restrict outgoing DNS traffic from your network except through the DNS servers provided by the DHCP server. You can create a firewall rule for this purpose.
18
19
In the left menu, navigate to IP and then click on Firewall.
20
21
Add a new rule to block DNS traffic going to any DNS server except those provided by your DHCP server.
22
23
plaintext
24
Copy code
25
/ip firewall filter
26
add chain=forward action=drop protocol=udp dst-port=53 out-interface=!your_WAN_interface
27
add chain=forward action=drop protocol=tcp dst-port=53 out-interface=!your_WAN_interface
28
Replace your_WAN_interface with the actual name of your WAN (Internet-facing) interface.
29
30
Update Configuration:
31
32
After making these changes, make sure to click "Apply Configuration" to save the changes.
33
Please note that implementing such restrictions might impact legitimate configurations or user preferences. Ensure that your network users are informed of any changes, and consider implementing such restrictions only if necessary for security or policy reasons.