Probably the most secure approach that gives best access would be to follow that link. Assuming you havve everyone configured with the OpenDNS servers for DNS, make a Network Group "OpenDNS Servers" = {208.67.220.220 & 208.67.222.222} and use it in a packet filter rule 'Internal (Network) -> DNS -> OpenDNS Servers : Allow'.
Probably the most secure approach that gives best access would be to follow that link. Assuming you havve everyone configured with the OpenDNS servers for DNS, make a Network Group "OpenDNS Servers" = {208.67.220.220 & 208.67.222.222} and use it in a packet filter rule 'Internal (Network) -> DNS -> OpenDNS Servers : Allow'.