Link to home
Start Free TrialLog in
Avatar of michaelsjacob
michaelsjacob

asked on

SBS 2003 need to restrict web access for some -- best method

okay, i am not sure which way i need to go with this...  here is what i've been asked to do...

office of about 50 users
sbs2003 server
sonicwall pro 300 firewall/router - providing dhcp leases & vpn connectivity
about 10 of the users will have full access to all external websites, the rest will be restricted to a list of approved sites.

in addition, those same groups will either have full email attachment/mime access, or be limited to word/pdf only.

now, can i do all of this in a set of GPOs, or do i have to do something different?


thanks for any help,
-mike.
Avatar of michaelsjacob
michaelsjacob

ASKER

would a custom host file pushed to the specific clients work?  since only certain sites will be available, i could remove the DNS server, and just use the Host file to route traffic... i think.  ;-)

any help would be great... i want to do this over the holiday weekend.
ASKER CERTIFIED SOLUTION
Avatar of Steven O'Neill
Steven O'Neill
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
standard.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
no worries... how about this idea -- just got it while on my "think tank"  ;-)

set-up one of our old, retired servers to run as a proxy... then direct one group of users to the proxy for the "limited accesss"  and the other group to the SBS for full dns access....

could it work?  our most recent retired box has win2k and exchange 5.5

-mike.
Your proxy box can restrict some users and allow others per your choice...

I have used WinProxy ( http://www.winproxy.com/index.asp) in the past with great success...and it runs on a desktop OS (like XP or Win2k Pro)  if you don't have a server with a licensed OS to use..