Dean Posted January 31, 2007 Posted January 31, 2007 Does anyone block individual students from accessing the internet for fixed periods of time? If you do could you tell me what method you have found to be the best and easiest to manage? Thanks
ChrisH Posted January 31, 2007 Posted January 31, 2007 Hello and welcome. Theres a big topic in here http://www.edugeek.net/index.php?name=Forums&file=viewtopic&t=4 This section is fairly new so I suppose that topic should be shifted over here.
webman Posted January 31, 2007 Posted January 31, 2007 Yes we do. Our CC3 network has a specific feature for this, which is essentially a security group that the "baddies" are added to and forces an invalid proxy server via GPO.
NetworkGeezer Posted January 31, 2007 Posted January 31, 2007 When you say fixed periods do you mean a kind of scheduled blocking?
NetworkGeezer Posted January 31, 2007 Posted January 31, 2007 When you say fixed periods do you mean a kind of scheduled blocking?
Dean Posted February 1, 2007 Author Posted February 1, 2007 Yes We have a big problem with game playing and kids using proxy sites to access Bebo and other such sites that are banned, and so its been decided that we block internet access for those students for set periods of time. Thanks
ChrisH Posted February 1, 2007 Posted February 1, 2007 When I can do it my strategy will be to ban Flash except for whitelisted sites. Do some clever keyword blocking with regards to PHP and Java games but maybe even put Java on whitelist sites. At the moment im banning sites and using phrase combinations such as "free online games" etc they get past this by searching for stuff such as copter games and such but I soon cotton on to those as they appear high in the rankings or I see them typing the terms into google on teh monitoring system.
Jake Posted February 1, 2007 Posted February 1, 2007 We have a banned usergroup on our ISA server, whenever a kid is caught on a site he/she shouldnt be on, we add them to the banned usergroup for 1-3 weeks (depending on the site). The site is then added to our ISA blacklist , which is now ridiculously huge
tom_newton Posted February 1, 2007 Posted February 1, 2007 We find most of our customers in education do some time based filtering - esp. boarding schools where it's often a case of dropping access after 10pm etc.
Dean Posted February 1, 2007 Author Posted February 1, 2007 We have a banned usergroup on our ISA server, whenever a kid is caught on a site he/she shouldnt be on, we add them to the banned usergroup for 1-3 weeks (depending on the site). The site is then added to our ISA blacklist , which is now ridiculously huge We have an ISA server, is it very easy to setup? As I am new to ISA.
Jake Posted February 1, 2007 Posted February 1, 2007 yeah its pretty straight forward, we just made a new group in the Users section of the toolbox called Banned, and then we created a new rule in the firewall policy that we called Block, with the attributes Deny , All Outbound Traffic, from internal to external , with the condition being the user is in the Banned group. Whenever we need to ban a pupil from internet access, we add their name to the Banned group, then when the ban is over we remove their name from the banned group.
Dean Posted February 1, 2007 Author Posted February 1, 2007 yeah its pretty straight forward, we just made a new group in the Users section of the toolbox called Banned, and then we created a new rule in the firewall policy that we called Block, with the attributes Deny , All Outbound Traffic, from internal to external , with the condition being the user is in the Banned group. That works a treat thanks
dezt Posted February 1, 2007 Posted February 1, 2007 @Jake Is that instant, or does it take a while to block the internet? We run wingate and i'm sick of having to allow internet usage to pupils, i'd rather be able to have everyone have access unless they needed blocking.
Jake Posted February 1, 2007 Posted February 1, 2007 Its instant, the moment they attempt to continue to browse , it comes up with our "your web access has been revoked" screen (there is a html file in the ISA installation which you can customise), so we have stuck our school badge and some messages on the page.
dezt Posted February 1, 2007 Posted February 1, 2007 Thanks Jake, looks like I can start hatching a plan to get rid of this damn wingate server.
Dean Posted February 2, 2007 Author Posted February 2, 2007 Its instant, the moment they attempt to continue to browse , it comes up with our "your web access has been revoked" screen (there is a html file in the ISA installation which you can customise), so we have stuck our school badge and some messages on the page. Hi Jake That’s the one thing I don’t seem to be able to get to work is the re-direct page, also I started to wonder if I can set a white allowed list so that they can still reach education sites like samlearning. Do you know where the re-direct page is stored? Dean
Jake Posted February 2, 2007 Posted February 2, 2007 Heya Dean, sure thing, at your installation directory, in our case c:\program files\ microsoft isa server, you should have a directory called Errorhtmls. In here are some html files which ISA redirects to, we changed some of those so that it would show a customised page, if I remember correctly we changed the default.htm and 407.htm Yeah you can set a white list, we run one here, under the toolbox in ISA we went to Network Objects, and created a new URL set called Whitelist, then we made a firewall rule allowing outbound traffic from internal to the whitelist.
Jake Posted February 2, 2007 Posted February 2, 2007 Re-reading it , I think you mean so that the banned students can still access education sites. We havent done that, the banned students are just totally banned, but looking over ISA I should think its possible to still allow them to view specific sites. Havent tried it, but I would think that maybe making a firewall rule which allowed banned to go internal to whitelist (rather than external), and positioning that rule above the internal to external banned rule should work?
Disease Posted February 2, 2007 Posted February 2, 2007 It's all down to postioning. Any combination is available you just need the positioning right.
t_guest Posted February 14, 2007 Posted February 14, 2007 why dont you try lan view 3 there is a section called i am disabled and manny more apps.you can disable just drag them in the section and set the time or days they will be blocked for.......
Jake Posted February 14, 2007 Posted February 14, 2007 why dont you try lan view 3 there is a section called i am disabled and manny more apps.you can disable just drag them in the section and set the time or days they will be blocked for....... In our case, because we already use an ISA server for internet management and filtering, so why use another application as well when we can do it with the ISA server we already have
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now