Grandstream
Overview
If you have not yet registered for our filtering service, you can do so by visiting our registration page.
First, you need to change the DNS settings of your device. To do this, click on the Network Settings side menu and look for the WAN item. Next, click the pen icon under Operations for your chosen WAN interface.
Set the WAN according to your desired connection mode like DHCP, Static IP, or PPPoE, and manually set the DNS addresses. Enter 185.236.104.104 inside the Primary DNS IP field and 185.236.105.105 in the Secondary DNS IP field.
Configure Dynamic DNS Service
To configure the Dynamic DNS service, open the External Access menu and click on the DDNS item. Then, configure the various fields exactly as follows:
- Service Provider: Select Dyndns.org.
- User Name: Enter the specific username assigned to your dynamic network inside our dashboard. Do not use your main account email address.
- Password: Enter the specific password assigned to your dynamic network.
- Domain: Enter the exact domain checkip.dyndns.org.
- Interface: Select the specific interface on which you want to configure the dynamic DNS service.
Click on the Save button to apply your changes.
It is absolutely not necessary to be registered with the DynDns.org service. Our setup will still work perfectly since our servers automatically intercept and redirect the update requests to themselves.
Deny DNS Changes by Users
Finally, you can inhibit clients from using alternative DNS servers to bypass the filter. You need to create firewall rules to block all traffic on port 53 for both TCP and UDP protocols, except for requests directed specifically to our cloud IPs.
Click on the Firewall menu and then on the Traffic Rules item. Within the Forwarding Rules section, click on Add to create your new rules following this exact priority order:
- Allow Primary DNS: Create a first rule to explicitly allow traffic directed to our primary filter DNS, which is 185.236.104.104.
- Allow Secondary DNS: Create a second rule to explicitly allow traffic directed to our secondary filter DNS, which is 185.236.105.105.
- Block All Other DNS: Finally, create a third rule to block all other DNS traffic on port 53. It is crucial to place this block rule after the two allow rules to ensure your network can still resolve approved requests.