Monday, June 09, 2008 at 4:10 pm by Brady Wilson

Protecting the minds and hearts of our children with OpenDNS

opendns_logo_300.gifThere is no argument that there is a lot of crap on the Internet.  And I am not referring to poorly designed web sites, time wasting games and an overabundance of news about absolutely everything.  The deep, dark alleys of the Internet (and sometimes not all that far removed) are filled with pornography, crime, drugs, hate and all manner of content I do not want my children to stumble upon and be subjected to.  Regardless of what some people may say about open mindedness and tolerance I won’t have it. Garbage in equals garbage out.

img_2448_0.jpgFor that reason, several of us here at Opus who have young children have implemented a free service from OpenDNS.com on our home networks.  Put simply OpenDNS offers filtered DNS resolution services for a network or specific devices.

More specifically OpenDNS provides DNS resolution services for your home, school or business network that filters phishing and adult content websites based on a category system. features_phishing.giffeatures_adult.gif You can specify how stringent you are with the filtering by selected various category types.  In addition you can block specific websites that would not normally be blocked such as Youtube and Myspace or other such “gray area” sites.

My purpose for using the service is to protect what is viewed from my home network.  Utility of the service does not stop there however.  As a business it could be use to filter webmail sites, job search sites, and other content based on HR policies.  A school may use it to protect students not only from harmful content but maybe also from social networking sites and other sites not appropriate for the school day.

As a user of the service you have access to a dashboard where you can control how your filtering works and view reports of usage on your network.  The service is free and paid for by ads placed on search result pages.

Implementation is as easy as creating an account then configuring your computer to use the OpenDNS servers as your DNS resolution servers.  The service can be configured to work with a dynamic DNS service so that you don’t have to have a static IP address from your provider to still make use of the service.

The best way to implement the use of OpenDNS on your network is to add the OpenDNS servers to the DHCP scope options on your network so that all computers on your network automatically use the OpenDNS servers.whatisdns_filtering.gif

This of course isn’t fool-proof as all it would take in this scenario to skirt the use of OpenDNS is changing the DNS server settings on the computer.  Most young children will not know anything about how to make these kinds of changes.  Also, in the near future with the adoption of IPv6 into the home, self configuration of IP addressing will become much more difficult increasing the dependence on DHCP and DNS services making it easier to force the use of the desired DNS servers.  There are more concrete ways to protect against getting around the use of OpenDNS but we won’t discuss them here.

I feel one of the greatest benefits of the OpenDNS service is that it can be a set it and forget it service for home use.  Once my firewall at home had its DHCP service configured with the OpenDNS DNS servers and I configured my filter settings at the OpenDNS site I knew that the devices on my network were protected.  Being an IT nerd and hobbyist I would love to roll my own filter using Squid, filtering built in to a firewall, or any other slick method to protect my network.  But who has the time?  I wouldn’t want my kids to stumble onto something (What are those daddy?) because I didn’t have the time to keep the filtering service updated or operational.  While no filtering is 100% it is OpenDNS who keeps the content on the internet categorized and blocked.  I don’t have to do it. 

Check out the OpenDNS.com website to learn more about this really cool service.  A full list of features is on their site here (http://www.opendns.com/features/overview/)
Use OpenDNS

Article Topics

Alternative Article:
Reinstalling RocketRaid drivers after updating FreeBSD

August 19, 2008

After going through the steps to update FreeBSD via cvsup, 3 of the servers didn’t come back up after reboot as fast as the other servers I updated did. After 10 minutes, of the server not coming back up, I realized something likely happened to the raid controller driver that these 3 servers use.
Once I [...]

Leave a Comment

You must be logged in to post a comment.

Article Archives:

  • Reinstalling RocketRaid drivers after updating FreeBSD

    After going through the steps to update FreeBSD via cvsup, 3 of the servers didn’t come back up after reboot as fast as the other servers I updated did. After 10 minutes, of the server not coming back up, I realized something likely happened to the raid controller driver that these 3 servers use.
    Once I [...]

    August 19th, 2008

  • Patching BIND for OpenBSD

    Recent security research discovered that there were multiple DNS implementations vulnerable to cache poisoning.This is a multi-vendor vulnerability outlined at the following links (among many others):
    http://secunia.com/cve_reference/CVE-2008-1447
    http://www.kb.cert.org/vuls/id/800113
    In our DNS infrastructure we separate the recursive query DNS servers from the authoritative DNS servers.  We limit recursive queries to our own network ranges.  Our internal DNS servers used [...]

    August 8th, 2008

  • The Real Ironman

    June 28th, 2008
     
    So, I just completed my 1st 1/2 Ironman Triathlon today.  It has been a goal that I have wanted to accomplish for some time.  After 5 months of vigorous training, I had one day to swim 1.2 miles in the frigid Wickiup Reservoir,
     
    ( bike 56 miles around Mt. Bachelor going from 4200 [...]

    August 5th, 2008

  • Virtualized for Non-Profit

    Opus Interactive has virtualized 22 of their servers in a effort to upgrade internal systems.  Instead of trying to sell the servers, or reprovision them, Opus Interactive decided the best thing to do is to donate them to Omni Media Networks Inc.  The donated servers were needed in an effort to expand Omni Media Networks Internet outreach programs.  Opus Interactive is very [...]

    July 1st, 2008

  • If a tree gets planted in the forest will anyone hear?

    Opus Interactive has joined with Arbor Day Foundation in their mission to “…inspire people to plant, nurture and celebrate trees.”  Arbor Day Foundation is the largest nonprofit tree-planting organization, with nearly one million members and averages over 12 million trees planted each year.
    So with that, the question becomes with almost 12 million trees each year, why [...]

    June 16th, 2008

Article Comments:

0 Comments