MikroTik Tutorial 63 - Prevent users from changing their DNS

Поділитися
Вставка
  • Опубліковано 7 вер 2024
  • Learn MikroTik RouterOs Tutorial Series (english)
    In this tutorial you will learn how to Prevent users from changing their DNS by forcing them to a specific DNS server.
    Mikrotik supported devices
    RB951Ui-2nD,hAP
    RB3011UIAS-RM
    RB2011UiAS-2HnD-IN
    RB750Gr2
    hEX,RB750Gr3
    RB2011iLS-IN
    CRS109-8G-1S-2HnD-IN
    hAP lite
    hAP ac mAP
    wAP
    RB951Ui-2HnD
    RB951G-2HnD
    RB2011UiAS-2HnD-IN
    RB941-2nD-TC
    RB2011iL-RM
    RB2011UiAS-IN
    RB2011UiAS-RM
    RB1100AHx4
    CCR1009-7G-1C-PC
    CCR1009-7G-1C-1S+PC
    LDF 5
    SXTsq Lite5
    DISC Lite5
    SXT Lite2
    SXTsq 5 ac
    LHG 2
    Groove 52
    LHG 5
    LHG XL 2
    LHG HP5
    SXT 2
    LHG
    OmniTIK 5
    BaseBox
    wAP 60G,SEXTANT G
    OmniTIK 5
    mANTBox
    QRT
    DynaDish

КОМЕНТАРІ • 62

  • @iconnectbymvgozalo6416
    @iconnectbymvgozalo6416 Рік тому

    Thank you very much! Very straight to the point tutorials.

  • @hazartilirot1014
    @hazartilirot1014 3 роки тому

    The tip is useful. I can force users to force my inner DNS server but what should be done provided the DNS server at the same subnet - it cannot resolve host :D

  • @dffabryr
    @dffabryr 5 років тому

    Your tutorials are very useful and effective. Thank you very much !!

  • @mahmoudegypt17
    @mahmoudegypt17 2 роки тому

    Your tutorials are very useful

  • @franzlestermeusebio3186
    @franzlestermeusebio3186 3 роки тому

    Thank you for this tutorial, is really works to me.

  • @brotheradamfromups
    @brotheradamfromups Рік тому

    How do I get this to work running a local pihole DNS that blocks certain domains and forwards all other requests to google dns?

  • @shokowillard
    @shokowillard 6 років тому +1

    Great tutorial keep up the great work. May you please add tutorial for different wireless modes (station,station pseudobridge,pseudobridge clone, station wds,nstreme dual slave etc)

    • @TKSJa
      @TKSJa  6 років тому +1

      Adding to my list.

  • @richardayuyang632
    @richardayuyang632 Рік тому

    How about multiple redirections to multiple DNS, I have 2 piholes in my network. TIA

  • @MaestroDJDaniello
    @MaestroDJDaniello 2 роки тому

    Awesome, thanks

  • @hijackthat974
    @hijackthat974 Рік тому

    this is so good, however can you tell us how to block users that use DoT or DoH?

  • @nexuspro183
    @nexuspro183 4 роки тому

    Really amazing series dude

  • @challenger5775
    @challenger5775 6 років тому

    its very useful. great tutorials.

    • @TKSJa
      @TKSJa  6 років тому

      Thanks

  • @TheRashyyd
    @TheRashyyd 2 роки тому

    My net stops browsing the minute I apply this changes, can you guess what could be the problem?

  • @adammostafa5426
    @adammostafa5426 2 роки тому

    is there an alternative way for zte router ?? . and thanke you for you amazing tutorials

  • @derrickt.za1564
    @derrickt.za1564 2 роки тому

    Can you please do a tutorial on user manager 7.1.2 version. I cannot get user to connect to the internet. Thank You

  • @JaZzDeOliveira
    @JaZzDeOliveira 4 роки тому

    Hi , how do I get this to work when running multiple Mikrotik Hotspots?
    I have two seperate hotspots. 1 is for guest and 1 is for kids. I have set a different DNS for each subnet. But after users sign in on the login page, I see that all DNS queries are sent to the DNS set on the Mikrotik router and even with the above NAT rule specifying to go external DNS.
    All DNS queries are still going to the Router DNS and not to the set DNS.
    Any suggestions on how to fix this, as the issue only occurs when using Hotspot.

  • @ncduong
    @ncduong 3 роки тому

    Hello, I install AdguardHome on RasPi, AdGuardHome DNS uses port 53 to listen. Unfortunately port 53 is also being used by Router Mikrotik's Hostspot service. How can I fix it? :(

  • @kevinmiole
    @kevinmiole Рік тому

    how to you add alternate dns? separate addresses with what?

  • @spiritcore1
    @spiritcore1 4 роки тому

    Very useful, thank you!
    Do you know why it blocks ping from my PC?
    Everything works OK but I can't ping when the rule is enabled...

  • @grimpr
    @grimpr 6 років тому +1

    Thanks, how do you redirect to the local mikrotik dns server that forwards to opendns?

    • @jotne
      @jotne 6 років тому +2

      Instead of setting Action: dst-nat, use Action: redirect and set To Port: 53. This will redirect all UDP:53 request to local DNS.

  • @AndrewTaranovND
    @AndrewTaranovND 5 років тому

    Thnx!

  • @JaZzDeOliveira
    @JaZzDeOliveira 3 роки тому

    This rule does not seem to work anymore, any suggestions with the new routeros version

  • @RaviPatel-fq8lq
    @RaviPatel-fq8lq 4 роки тому

    hi i want to Force users to use specified our DNS server on mikrotik can we use the rule

  • @amieka7454
    @amieka7454 3 роки тому

    Can I use this rule for multiple DNS ?

  • @SpikeHome
    @SpikeHome 6 років тому

    great tutotrial, but kan i also force users to use my local dns cache server at my mikrotik router?

    • @TKSJa
      @TKSJa  6 років тому

      yes, just change the IP to your dns IP.

  • @stevesmith2553
    @stevesmith2553 6 років тому

    can you do one on layer 3 switching ., routing on a layer 3 switch --- ty

    • @TKSJa
      @TKSJa  6 років тому

      Noted

  • @potskie3704
    @potskie3704 6 років тому

    Hi, i just want to know if mikrotik can also prevent user to share their internet to other wifi devices.

    • @TKSJa
      @TKSJa  6 років тому

      It all depends on how your network is configured. Based on my experience this might not be preventable.

  • @dangdut1
    @dangdut1 6 років тому

    hello sir
    I want to ask if you not mind
    about rule for extension video download on layer7 can you tell us ?? I use rb952.. many tutorial i try can't recognize in winbox.. the mangle packet still zero

    • @TKSJa
      @TKSJa  6 років тому

      Check the interfaces that you are using in your mangle rules.

  • @maltew7653
    @maltew7653 6 років тому

    What should i do if i want to force everyone trough a pihole dns , expect the raspberry pi , so pihole can forward passed trafic trough another dns like: 9.9.9.9

    • @TKSJa
      @TKSJa  6 років тому +1

      Create an exception in the rule for that address.

    • @maltew7653
      @maltew7653 6 років тому

      TKSJa OK thanks...if the DNServer , in my case pihole is on the local lan can i do the setup like shown in the Video or should i use another nat action?

  • @DolcheGuevara
    @DolcheGuevara 6 років тому

    You haven`t show us what happent if someone change DNS in network settings.

    • @JoshSmeda
      @JoshSmeda 5 років тому +2

      Won't affect client side. The masquerade rule will redirect DNS traffic to the destination you specified in the rule. If you want to enforce client side, setup a group policy. This is a workaround for a non AD environment.

  • @dennytobing
    @dennytobing 6 років тому

    how about with 2 ISP Connection ?

    • @TKSJa
      @TKSJa  6 років тому

      Create a rule for each connection.

  • @kazimriaz8319
    @kazimriaz8319 5 років тому

    very helpful can you tell me the model of this device ?

    • @TKSJa
      @TKSJa  4 роки тому

      Don't remember, all Mikrotik routers can do this

  • @johnlohan9900
    @johnlohan9900 6 років тому

    Please tell me why it is important to do this ?

    • @TKSJa
      @TKSJa  6 років тому

      Content filtering and security.

  • @usmanjutt7908
    @usmanjutt7908 6 років тому

    Hlow sir i say again
    How to limit dwonlad extenshion mkv mp4 and etc😆😊☺

    • @TKSJa
      @TKSJa  6 років тому

      Added to my list.

  • @ahmdnaube3745
    @ahmdnaube3745 3 роки тому

    After this setup what if a client uses his Android to install a VPN app and connect that APP then he can browse porn? Am i right?

  • @redheart419
    @redheart419 6 років тому

    Isn't it illegal when ISP doing this?

    • @TKSJa
      @TKSJa  6 років тому

      No sure, but for hotspot, business, school or home this is ok to do.

    • @redheart419
      @redheart419 6 років тому

      +TKSJa I'm talking about residential broadband provider

    • @redheart419
      @redheart419 6 років тому

      +TKSJa it's acceptable for school, businesses and Hotspot... But when residential broadband provider does this, it pisses off some advance users

    • @TKSJa
      @TKSJa  6 років тому

      That's true

  •  6 років тому

    No alternate DNS?

    • @TKSJa
      @TKSJa  6 років тому

      No, you set yours

    • @obslugait88
      @obslugait88 5 років тому

      @@TKSJa What if I use router DNS and Cache?

    • @rodrickingram8731
      @rodrickingram8731 5 років тому

      @@obslugait88 You could

  • @ArmanHAlam
    @ArmanHAlam 4 роки тому

    Firewall / NAT rule for forcing use of google isnt wokring