Home

Is it possible to control DNS client on Win 10

%3CLINGO-SUB%20id%3D%22lingo-sub-1260168%22%20slang%3D%22en-US%22%3EIs%20it%20possible%20to%20control%20DNS%20client%20on%20Win%2010%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1260168%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EAs%20we%20all%20know%2C%20the%20DNS%20is%20one%20of%20the%20services%20which%20is%20leaking%20information%20out%20from%20the%20organizations.%20I%20have%20read%20some%20plans%20to%20have%20possibilities%20to%20do%20filtering%20how%20much%20DNS%20servers%20are%20leaking%20data%20out.%20But%20in%20case%20your%20workstation%20is%20living%20two%20two%20different%20life%3A%20VPN%20and%20without%20VPN.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20normally%20when%20workstation%20is%20having%20VPN%20established%2C%20all%20the%20DNS%20queries%20are%20of%20course%20traveling%20through%20the%20VPN.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20when%20domain%20joined%20workstation%20is%20starting%20without%20VPN%20it%20is%20shooting%20many%20different%20internal%20DNS%20queries%20to%20the%20first%20available%20DNS%20server.%20And%20as%20we%20all%20know%2C%20those%20queries%20are%20plain%20text%20on%20the%20wire.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHas%20any%20on%20here%20tried%20to%20solve%20this%20issue%20somehow%3F%20Having%20own%20DNS%20client%20for%20VPN%20and%20closing%20down%20OS's%20own%20DNS%20client%3F%20Or%20filtering%20DNS%20queries%20for%20internal%20domains%20by%20local%20FW%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1260168%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Edata%20leaking%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EDNS%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EDomain%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1274210%22%20slang%3D%22en-US%22%3ERe%3A%20Is%20it%20possible%20to%20control%20DNS%20client%20on%20Win%2010%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1274210%22%20slang%3D%22en-US%22%3E%3CP%3EOh!%20I%20was%20sure%20to%20get%20quick%20solution%20for%20this%20from%20here%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%20though%20(or%20wild%20idea)%2C%20as%20Windows%20defender%20cannot%20filter%20unwanted%20DNS%20queries%20(%3F).%20Would%20it%20be%20the%20only%20option%20to%20install%20a%20local%20DNS%20server%20to%20all%20of%20the%20workstations%20and%20force%20a%20dns%20client%20to%20use%20that.%20In%20the%20local%20DNS%20server%20we%20could%20define%20forwarders%20for%20the%20internal%20domains.%20This%20way%20internal%20queries%20are%20not%20sent%20out.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20not%20internal%20DNS%20queries%2C%20we%20need%20to%20query%20the%20DNS%20servers%20from%20the%20DHCP%20and%20forward%20the%20rest%20of%20the%20DNS%20queries%20to%20those%20DNS%20servers.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1399413%22%20slang%3D%22en-US%22%3ERe%3A%20Is%20it%20possible%20to%20control%20DNS%20client%20on%20Win%2010%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1399413%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F90197%22%20target%3D%22_blank%22%3E%40Petri%20X%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20there%3C%2FP%3E%3CP%3EI%20am%20still%20thinking%20about%20a%26nbsp%3B%20proper%20solution...%20But%20frankly%20speaking%2C%20it%20is%20difficult%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3EHowever%2C%20if%20you%20route%20all%20the%20traffic%20through%20the%20VPN%20you%20could%20leave%20the%20dns%20servers%20blank%20and%20only%20add%20the%20url(s)%20needed%20for%20the%20vpn%20connection%20to%20the%20local%20hosts%20file.%20Everything%20else%20would%20then%20be%20resolved%20via%20the%20DNS%20servers%20provided%20through%20the%20vpn%20connection.%3C%2FP%3E%3CP%3EBut%20either%20way%20(hosts%20file%20oder%20local%20dns%20resolver)%20seems%20to%20be%20more%20like%20a%20workaround%20than%20a%20proper%20solution...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1416511%22%20slang%3D%22en-US%22%3ERe%3A%20Is%20it%20possible%20to%20control%20DNS%20client%20on%20Win%2010%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1416511%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EMove%20to%20the%20services%20tab%2C%20and%20Locate%20DNS%20Client%20from%20the%20available%20services.%20If%20you%20wish%20to%20Disable%20DNS%20Client%20Service%2C%20untick%20the%20checkbox%20of%20the%20same.%20And%20To%20keep%20the%20service%20enabled%2C%20simply%20click%20on%20the%20checkbox%20to%20keep%20the%20tick%20mark.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1416705%22%20slang%3D%22en-US%22%3ERe%3A%20Is%20it%20possible%20to%20control%20DNS%20client%20on%20Win%2010%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1416705%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F378366%22%20target%3D%22_blank%22%3E%40Smith_J%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3EI'm%20not%20sure%20could%20that%20do%20what%20I%20asked%3F%20I%20do%20not%20want%20to%20disable%20DNS%20as%20that%20is%20core%20component%20in%20computer%20world.%20The%20problem%20is%2C%20when%20you%20do%20not%20have%20VPN%20connection%20established%20your%20workstation%20is%20sending%20a%20lot%20of%20DNS%20queries%20to%20the%20DNS%20server%20on%20your%20NIC%20configuration.%20I%20was%20only%20hunting%20a%20possibility%20to%20block%20our%20internal%20FQDNs%20to%20be%20sent%20to%20external%20DNS%20server%20when%20VPN%20is%20not%20ready%20yet.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EObviously%20our%20internal%20FQDNs%20are%20not%20resolvable%20on%20public%20network%2C%20but%20also%20if%20someone%20listening%20the%20traffic%20they%20could%20learn%20our%20infrastructure%20(data%20leaking)%2C%20but%20also%20sometime%20even%20user%20IDs%20are%20sent%20out.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWould%20be%20nice%20to%20be%20able%20to%20setup%20a%20conditional%20forwarders%20for%20our%20internal%20domains%20to%20known%20internal%20DNS%20servers%20only.%20Unfortunately%20such%20a%20term%20as%20%22conditional%20forwarder%22%20is%20an%20option%20only%20on%20DNS%20servers%20and%20not%20for%20DNS%20clients.%20But%20if%20that%20could%20be%20possible%2C%20then%20when%20the%20VPN%20is%20not%20established%2C%20those%20internal%20DNS%20queries%20are%20not%20sent%20out%20as%20internal%20DNS%20servers%20are%20not%20reachable%2C%20until%20VPN%20is%20working%20again.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Regular Contributor

Hi,

As we all know, the DNS is one of the services which is leaking information out from the organizations. I have read some plans to have possibilities to do filtering how much DNS servers are leaking data out. But in case your workstation is living two two different life: VPN and without VPN.

 

So normally when workstation is having VPN established, all the DNS queries are of course traveling through the VPN.

 

But when domain joined workstation is starting without VPN it is shooting many different internal DNS queries to the first available DNS server. And as we all know, those queries are plain text on the wire.

 

Has any on here tried to solve this issue somehow? Having own DNS client for VPN and closing down OS's own DNS client? Or filtering DNS queries for internal domains by local FW?

4 Replies
Highlighted

Oh! I was sure to get quick solution for this from here :)

 

Just though (or wild idea), as Windows defender cannot filter unwanted DNS queries (?). Would it be the only option to install a local DNS server to all of the workstations and force a dns client to use that. In the local DNS server we could define forwarders for the internal domains. This way internal queries are not sent out.

 

For not internal DNS queries, we need to query the DNS servers from the DHCP and forward the rest of the DNS queries to those DNS servers.

Highlighted

@Petri X 

Hi there

I am still thinking about a  proper solution... But frankly speaking, it is difficult :)

However, if you route all the traffic through the VPN you could leave the dns servers blank and only add the url(s) needed for the vpn connection to the local hosts file. Everything else would then be resolved via the DNS servers provided through the vpn connection.

But either way (hosts file oder local dns resolver) seems to be more like a workaround than a proper solution...

Highlighted

Move to the services tab, and Locate DNS Client from the available services. If you wish to Disable DNS Client Service, untick the checkbox of the same. And To keep the service enabled, simply click on the checkbox to keep the tick mark.

Highlighted

Hi @Smith_J ,

I'm not sure could that do what I asked? I do not want to disable DNS as that is core component in computer world. The problem is, when you do not have VPN connection established your workstation is sending a lot of DNS queries to the DNS server on your NIC configuration. I was only hunting a possibility to block our internal FQDNs to be sent to external DNS server when VPN is not ready yet.

 

Obviously our internal FQDNs are not resolvable on public network, but also if someone listening the traffic they could learn our infrastructure (data leaking), but also sometime even user IDs are sent out.

 

Would be nice to be able to setup a conditional forwarders for our internal domains to known internal DNS servers only. Unfortunately such a term as "conditional forwarder" is an option only on DNS servers and not for DNS clients. But if that could be possible, then when the VPN is not established, those internal DNS queries are not sent out as internal DNS servers are not reachable, until VPN is working again.