-----BEGIN PGP SIGNED MESSAGE-----
On Mon, Sep 09, 2013 at 10:12:30AM -0700, Mark Duling wrote:
> For those who block outbound DNS going to outside dns servers, which
> servers do you allow? Google, OpenDNS, what else?
We even restrict those. All clients get an IP and primary, secondary and
tertiary DNS servers via DHCP. Each year we get a handful of users with
hard-coded DNS but they're sorted in short order. They're rarely for
Google DNS or OpenDNS, typically they're for an ISP "back home".
The amount of time spent helping all of them get sorted in an academic
year is less than the amount it takes to do clean-up on an infected
system because they're not using our DNS sinkhole.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
-----END PGP SIGNATURE-----
Participation and subscription information for this EDUCAUSE Constituent Group discussion list can be found at http://www.educause.edu/groups/.