Mr_M_Cox Posted July 7, 2009 Posted July 7, 2009 Hi All, I need to find a way to block users accessing the internet but still allow access to the intranet. The thing is it cant involve using Proxy settings as we have some software accessable to the users that will reset the proxy. Also needs to be easily done to alot of PC's over the network Any ideas are more than welcome as we are a bit stuck here. Thanks all
Edu-IT Posted July 7, 2009 Posted July 7, 2009 The thing is it cant involve using Proxy settings as we have some software accessable to the users that will reset the proxy.What I would have suggested is set the proxy to something non existant and bypass the proxy for local addresses but that isn't going to work then. What is the purpose of the software that you're talking about? Can you not get around it for these users?
BBeh Posted July 7, 2009 Posted July 7, 2009 Could you just blacklist everything, and just whitelist the intranet?
Mr_M_Cox Posted July 7, 2009 Author Posted July 7, 2009 How can I add the black/white list to all PC's across the network without having to go to each one? An no, I cannot get rid of the software, long story but no, i cant.
Edu-IT Posted July 7, 2009 Posted July 7, 2009 How can I add the black/white list to all PC's across the network without having to go to each one? Do you have any web filtering software?
f21970 Posted July 7, 2009 Posted July 7, 2009 I'd just buy Browsecontrol & use that. Then you can turn internet off and on when you need (or even better, delegate that function to teachers).
Mr_M_Cox Posted July 7, 2009 Author Posted July 7, 2009 Sorry, prob should have said straight away, I CANNOT buy or use any third party software. It HAS to be something found within windows XP, do able across many PC's easily and not involve the proxy. So far the best idea is content advisor but that is fine on one PC but not really scaleable across the network, that I know of! Thanks for all the help so far.
Edu-IT Posted July 7, 2009 Posted July 7, 2009 Sorry, prob should have said straight away, I CANNOT buy or use any third party software. It HAS to be something found within windows XP, do able across many PC's easily and not involve the proxy. So far the best idea is content advisor but that is fine on one PC but not really scaleable across the network, that I know of! Thanks for all the help so far. I think you're asking for the impossible.
featured_spectre Posted July 7, 2009 Posted July 7, 2009 possibly the use of an ISA server redirect? if they have access to the server, put ISA on, add your website blocks, and in theory it should work!
Mr_M_Cox Posted July 7, 2009 Author Posted July 7, 2009 Tell me about it, I really need to ind a solution but I am stumped. I am not allowed to add any software so that blew my third party software out of the window but the heads still want to maintain access to intranet and network so cant just remove access all together. Any other ideas please help. :-) Any more info on setting black/white lists on multiple PC's?
Edu-IT Posted July 7, 2009 Posted July 7, 2009 Tell me about it, I really need to ind a solution but I am stumped. I am not allowed to add any software so that blew my third party software out of the window but the heads still want to maintain access to intranet and network so cant just remove access all together. Any other ideas please help. :-) Any more info on setting black/white lists on multiple PC's? I'm intrigued. Why can't you add software to the network if it's the only way to achieve what you want to do and it'll benefit the school?
gwildebeast Posted July 7, 2009 Posted July 7, 2009 You might be able to do something with DNS by removing any forwarders and root hints from a specifically configured DNS server and using DHCP to direct all the computers you want to not have internet access to that server as their DNS. I haven't tried this but in theory it should work.
FN-GM Posted July 7, 2009 Posted July 7, 2009 You could add lines to the localhost file. No extra software needed at all. Z
Mr_M_Cox Posted July 7, 2009 Author Posted July 7, 2009 Because I have no money for it and they dont like free/shareware. Then If i do want to add it then I have to get it approved which takes ages.
pete Posted July 7, 2009 Posted July 7, 2009 Block them at the border firewall? Or do they need access to the internal LEA sites?
mossj Posted July 7, 2009 Posted July 7, 2009 Because I have no money for it and they dont like free/shareware. Then If i do want to add it then I have to get it approved which takes ages. WTH, they don't like free software..... Most schools utilize Open Source in one way or another. It wouldn't make sense to pay for something you can get for free elsewhere. Also you have to get it approved?!? by who? Thats insane...
Edu-IT Posted July 7, 2009 Posted July 7, 2009 Then If i do want to add it then I have to get it approved which takes ages.If the heads are asking for it then let them get it fast tracked. People on here won't recommend rubbish software, if that's your worry.
jamesb Posted July 7, 2009 Posted July 7, 2009 Can't you set the content advisor/security zone settings via group policy? At least it'd stop you having to visit all the computers.
BBeh Posted July 7, 2009 Posted July 7, 2009 Is there currently any web filtering set up on your systems? If there is, and you have access to it, you could just block everything you don't want, or just allow a certain few pages to be viewed. If not, it's looking more and more impossible.
Edu-IT Posted July 7, 2009 Posted July 7, 2009 Unplug your DSL/Fibre. Score!. That's okay until you need to send/receive email.
mac_shinobi Posted July 7, 2009 Posted July 7, 2009 (edited) If its just for certain users cant you put those users into a specific OU and get that OU to apply no proxy settings so that direct connections should work and if you go out to the internet it wont work because it should be blocked by proxy server ? Would have to test that ( if its for those computers in question then just drag those computer objects into that OU instead of the users ) Just a thought - saw below about pac file ( may be the way to go ) but again this will be proxy settings again so not sure if thats what you wanted Edited July 7, 2009 by mac_shinobi
SYNACK Posted July 7, 2009 Posted July 7, 2009 You could use Wmi script to blackhole the proxy server ip on the targeted stations: Route add (VBScript) - Windows Server Cookbook Managing IP Routes Through WMI
srochford Posted July 7, 2009 Posted July 7, 2009 Use IPSec Block Web Browsing but Allow Intranet Traffic with IPSec Block Web Browsing with IPSec Down at the bottom of the first article there's a link to configuring IPSec using GPO so you can get it on all machines.
jamie-a Posted July 7, 2009 Posted July 7, 2009 What about a custom pac file on a shared area for each room/group of pc`s done through an appropriate OU for each group, sending any non intranet traffic to a dummy proxy if net access is not needed
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now