Greets: I searched but didn’t see a specific post on this one–but maybe I missed it. I would like to require all internal users to only use OpenDNS. Here’s the way I think it should work, but I wanted to get a sanity check before I try it in production.
- OpenDNS addresses set on the routerboard for DNS (208.67.222.222, 208.67.220.220)
- Gateway address (w.x.y.1) pushed out via DHCP as the only DNS server address (w.x.y.1).
- Allow tcp/udp 53 to w.x.y.1 on internal
- Block tcp/udp 53 on internal
Not sure if step three is necessary…it would be on the same network… Appreciate any comments–pretty new to RouterOS, so be gentle with me ![]()