Forum Discussion

Fatal_Ignorance's avatar
Fatal_Ignorance
Copper Contributor
Feb 23, 2021

Disable built in DNS Completely

Hi, 

 

I was wondering if there were any plans to provide us the ability to completely disable the built in DNS with Edge. I understand that you can disable the DNS however this does not really resolve all the issues. 

 

I work at an organization that has it's intranet page as the default home page on all devices, on the internal DNS server we have it pointing to the intranet server obviously. However when users go home the external DNS server points that same URL to the external site page instead. We have the TTL on that record set to 30 seconds however when users come back in the site still points them to the external site. Running a ipconfig / flushdns does nothing. I found out that if you clear the browser cache it then resolves properly again. I am not entirely sure what is causing this but I'd really appreciate a fix for this or a way to manage this functionality. 

  • in Edge settings, set DNS to "Use current service provider"
    can be configed via group policy:

    https://docs.microsoft.com/en-us/deployedge/microsoft-edge-policies#dnsoverhttpsmode

    set that to "Off"
    The "off" mode will disable DNS-over-HTTPS.

    also disable this:
    https://docs.microsoft.com/en-us/deployedge/microsoft-edge-policies#use-built-in-dns-client

    more info:
    "This policy controls which software stack is used to communicate with the DNS server: the operating system DNS client, or Microsoft Edge's built-in DNS client. This policy does not affect which DNS servers are used: if, for example, the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It also does not control if DNS-over-HTTPS is used; Microsoft Edge always uses the built-in resolver for DNS-over-HTTPS requests. Please see the DnsOverHttpsMode policy for information on controlling DNS-over-HTTPS."

    "If you enable this policy, the built-in DNS client is used, if it's available.

    If you disable this policy, the built-in DNS client is only used when DNS-over-HTTPS is in use.

    If you don't configure this policy, the built-in DNS client is enabled by default."

     

    by the way, this part is a bit confusing: "However when users go home the external DNS server points that same URL to the external site page instead. "

     

    you only have a homepage URL which is a website hosted internally, then what is the external site page?

  • in Edge settings, set DNS to "Use current service provider"
    can be configed via group policy:

    https://docs.microsoft.com/en-us/deployedge/microsoft-edge-policies#dnsoverhttpsmode

    set that to "Off"
    The "off" mode will disable DNS-over-HTTPS.

    also disable this:
    https://docs.microsoft.com/en-us/deployedge/microsoft-edge-policies#use-built-in-dns-client

    more info:
    "This policy controls which software stack is used to communicate with the DNS server: the operating system DNS client, or Microsoft Edge's built-in DNS client. This policy does not affect which DNS servers are used: if, for example, the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It also does not control if DNS-over-HTTPS is used; Microsoft Edge always uses the built-in resolver for DNS-over-HTTPS requests. Please see the DnsOverHttpsMode policy for information on controlling DNS-over-HTTPS."

    "If you enable this policy, the built-in DNS client is used, if it's available.

    If you disable this policy, the built-in DNS client is only used when DNS-over-HTTPS is in use.

    If you don't configure this policy, the built-in DNS client is enabled by default."

     

    by the way, this part is a bit confusing: "However when users go home the external DNS server points that same URL to the external site page instead. "

     

    you only have a homepage URL which is a website hosted internally, then what is the external site page?

    • Fatal_Ignorance's avatar
      Fatal_Ignorance
      Copper Contributor
      Thanks for the reply and sorry for the late response! I am going to try your suggestions and get back to you.

      to clarify what I meant by "However when users go home the external DNS server points that same URL to the external site page instead. "

      The default home page for all our computers is Intranet.DOMAINNAME.com when users are on site the internal DNS points that url to the internally hosted intranet page that is ONLY accessible internally.

      Now, when users go home we have the external DNS server pointing Intranet.DOMAINNAME.com to the external site instead. Otherwise when they go home all our users would open their web browsers to an unresolvable page.

      We have the TTL on the DNS records set to 30 seconds so ideally it would check which ip it should connect to every time they open the browser on site or at home. Is that more clear ? sorry if I am not doing a great job at explaining myself.
      • HotCakeX's avatar
        HotCakeX
        MVP
        Thank you,
        by doing that you will neutralize Edge's DNS involvement.
  • JoeGoerlich's avatar
    JoeGoerlich
    Copper Contributor
    You run a so-called split-brain DNS setup. In this case you have to make sure the TTL of both internal and external A records is short enough to avoid the issues you mentioned. Also be aware that changes to TTL need some time to be replicated and the original TTL must be exceeded on all clients (or cache has to be flushed).
    You may rethink of you need to solve your issue with a split-Brain DNS or if NAT reflection would also be an option.

    Cheers
    Joe
    • Fatal_Ignorance's avatar
      Fatal_Ignorance
      Copper Contributor
      Thanks for that info, I had not thought about that but in our case that would not be an issue as we implemented that change long ago and have simply been dealing with the issues. This isn't really super high on our priority list but I figured I would ask the community.

Resources