DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
How to keep the kids safe???
- floriank
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 15
- Thank yous received: 0
28 Dec 2014 16:45 #82200
by floriank
I know that I can set the DNS server - currently using Google's 8.8.8.8 - in my router's LAN settings but I don't think I can set a different one in the SSID settings? Ideally, I'd like to set different DNS servers for the different wireless networks (SSIDs) so that one runs on Google for us parents and the other on OpenDNS for the kids but I don't think this is possible with a Draytek 2920?
I can set individual DNS servers on each PC but, as admin says, any of the more clever kids - no offence to the others;-) - will just set it back to Google's and I would be left checking the DNS settings on everybody's PC all the time to see whether they've been changed.
J1mbo, thanks for your thoughts and I agree with most of them but am still mystified how to stop unwanted apps on devices like iPods or Androids tablets running as they obviously don't use http URLs for connecting to their servers (I imagine). I guess even if I disable frankly.com or snapchat.com via OpenDNS, the Frankly and Snapchat iOS apps will still run?
Replied by floriank on topic Re: How to keep the kids safe???
You also need to set up an ip filter for DNS lookups, otherwise the 16 year old will just change the DNS server on his PC. Also, what does OpenDNS do for https lookups ?admin wrote:
I know that I can set the DNS server - currently using Google's 8.8.8.8 - in my router's LAN settings but I don't think I can set a different one in the SSID settings? Ideally, I'd like to set different DNS servers for the different wireless networks (SSIDs) so that one runs on Google for us parents and the other on OpenDNS for the kids but I don't think this is possible with a Draytek 2920?
I can set individual DNS servers on each PC but, as admin says, any of the more clever kids - no offence to the others
J1mbo, thanks for your thoughts and I agree with most of them but am still mystified how to stop unwanted apps on devices like iPods or Androids tablets running as they obviously don't use http URLs for connecting to their servers (I imagine). I guess even if I disable frankly.com or snapchat.com via OpenDNS, the Frankly and Snapchat iOS apps will still run?
Please Log in or Create an account to join the conversation.
- j1mbo
- Offline
- Member
Less
More
- Posts: 107
- Thank yous received: 0
28 Dec 2014 17:06 #82201
by j1mbo
Replied by j1mbo on topic Re: How to keep the kids safe???
Everything Internet works with DNS, regardless of whether it's an IOS App, a web page, or anything else. DNS is the phone book that translates host names to IP address. Have a look at
this for snapchat
for example.
Draytek routers support additional VLANs (sorry not sure about the router WiFi config as I've always deployed separate Access Points), but each of these can have separate DHCP options set, including DNS servers. A VLAN is a separate network - traffic between VLANs has to cross a routing device.
To keep things simple, you could enable VLANs on the Draytek (LAN/VLAN option) and set a particular physical Ethernet port of the Draytek router to be on LAN2 subnet. Then buy any WiFi access point (that isn't made by NetGear) and plug it in to that port. On the router, under LAN2 DHCP (LAN/General/LAN2/Details) set the DHCP servers to be OpenDNS, and on LAN1 set DNS servers to be Google. Next set up a new SSID on the new access point, and connect the devices to be filtered to that.
So it looks like this:
Draytek Router
+-> Built-in WiFi AP -> Unfiltered Wireless Clients (on LAN1)
+-> LAN2 subnet Ethernet port -> New Access Point -> Filtered Wireless Clients
Also - Draytek has a subscription based URL filtering solution I think that might do what you want.
Anyway, hope that helps!
Draytek routers support additional VLANs (sorry not sure about the router WiFi config as I've always deployed separate Access Points), but each of these can have separate DHCP options set, including DNS servers. A VLAN is a separate network - traffic between VLANs has to cross a routing device.
To keep things simple, you could enable VLANs on the Draytek (LAN/VLAN option) and set a particular physical Ethernet port of the Draytek router to be on LAN2 subnet. Then buy any WiFi access point (that isn't made by NetGear) and plug it in to that port. On the router, under LAN2 DHCP (LAN/General/LAN2/Details) set the DHCP servers to be OpenDNS, and on LAN1 set DNS servers to be Google. Next set up a new SSID on the new access point, and connect the devices to be filtered to that.
So it looks like this:
Draytek Router
+-> Built-in WiFi AP -> Unfiltered Wireless Clients (on LAN1)
+-> LAN2 subnet Ethernet port -> New Access Point -> Filtered Wireless Clients
Also - Draytek has a subscription based URL filtering solution I think that might do what you want.
Anyway, hope that helps!
Please Log in or Create an account to join the conversation.
- floriank
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 15
- Thank yous received: 0
29 Dec 2014 09:34 #82203
by floriank
Replied by floriank on topic Re: How to keep the kids safe???
Thanks J1mbo, this sounds like an option. It's a little out of my comfort zone, technically, but I will get my head round it somehow as I understand the thinking behind it.
Plenty of food for thought here, thank you all for your input - I will go away and put something together and report back for an update.
Great forum, thanks guys! Been a customer of Draytek for many years and currently use 16 of their routers in my business but none of them have ever needed this kind of granular filtering.
Plenty of food for thought here, thank you all for your input - I will go away and put something together and report back for an update.
Great forum, thanks guys! Been a customer of Draytek for many years and currently use 16 of their routers in my business but none of them have ever needed this kind of granular filtering.
Please Log in or Create an account to join the conversation.
- admin
- Offline
- Site Admin
Less
More
- Posts: 1723
- Thank yous received: 0
30 Dec 2014 15:32 #82214
by admin
Forum Administrator
Replied by admin on topic Re: How to keep the kids safe???
Users could just enter the IP address of an unsuitable site and bypass open dns altogether. I think global view with dns filter can prevent that.
Forum Administrator
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek