Advertisement

05.08.2008 at 02:21PM PDT, ID: 23387756 | Points: 500
[x]
Attachment Details
How do I prevent certain workstations from accessing internet in an SBS2003 environment?
I have a site that is using SBS2003 (not running ISA). There are certain workstations that must be able to access network drives, but not the internet. I've tried changing proxy and DNS settings manually, but the (night shift) staff who use those computers change the settings back so that they can access the internet again. This is an ongoing problem that needs to be addressed permanently.

Is there a way to prevent those particular workstations (or users) from accessing the internet using group policy? I'm not too familiar with Group Policy management, so a little guidance would be appreciated.

Start your free trial to view this solution
Question Stats
Zone: OS
Question Asked By: Wiltshire
Question Asked On: 05.08.2008
Participating Experts: 2
Points: 500
Views: 0
Translate:
Loading Advertisement...
05.08.2008 at 02:28PM PDT, ID: 21528638

Rank: Sage

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 02:54PM PDT, ID: 21528802

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 03:00PM PDT, ID: 21528840

Rank: Sage

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 03:22PM PDT, ID: 21528956

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 05:30PM PDT, ID: 21529618

Rank: Sage

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.09.2008 at 06:47AM PDT, ID: 21532717

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.09.2008 at 06:57AM PDT, ID: 21532822

Rank: Sage

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.09.2008 at 07:06AM PDT, ID: 21532924

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.09.2008 at 07:18AM PDT, ID: 21533067

Rank: Sage

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.09.2008 at 06:02PM PDT, ID: 21537436

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.09.2008 at 06:16PM PDT, ID: 21537470

Rank: Sage

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
Loading Advertisement...
Microsoft
  • Internet Protocols
  • Applications
  • Development
  • OS
  • Hardware
  • Windows Security
Apple
  • Operating Systems
  • Hardware
  • Programming
  • Networking
  • Software
Internet
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Spy / Ad Blockers
  • Web Browsers
  • New Net Users
  • Web Development
  • Chat / IM
  • Anti Spam
  • Web Servers
  • Anti-Virus
  • Email Clients
Gamers
  • Tips
  • Online / MMORPG
  • Puzzle
  • Emulators
  • Action / Adventure
  • Role Playing
  • Consoles
  • Game Programming
  • Strategy
  • Sports
  • Misc
  • Computer Games
Digital Living
  • Hardware
  • New Net Users
  • New Users
  • Software
  • Digital Music
  • Gaming World
  • Home Security
  • Apple
  • Networking Hardware
Virus & Spyware
  • Vulnerabilities
  • IDS
  • Encryption
  • Anti-Virus
  • Operating Systems Security
  • Software Firewalls
  • WebApplications
  • Cell Phones
  • Operating Systems
  • Internet
  • Hardware Firewalls
Hardware
  • Handhelds / PDAs
  • Displays / Monitors
  • Components
  • Networking Hardware
  • Peripherals
  • Laptops/Notebooks
  • Storage
  • Servers
  • Desktops
  • New Users
  • Misc
  • Apple
Software
  • System Utilities
  • Industry Specific
  • Network Management
  • Photos / Graphics
  • Page Layout
  • VMWare
  • Misc
  • Web Development
  • OS
  • CYGWIN
  • Voice Recognition
  • Message Queue
  • Quality Assurance
  • Security
  • Firewalls
  • MultiMedia Applications
  • Development
  • Database
  • Office / Productivity
  • Business Management
  • OS/2 Apps
  • Server Software
  • Internet / Email
ITPro
  • OS
  • Storage
  • Encryption
  • Operating Systems Security
  • Apple Hardware
  • Laptops & Notebooks
  • Servers
  • Networking Hardware
  • Peripherals
  • Devices
  • Displays / Monitors
  • WebTrends / Stats
  • Search Engines
  • Firewalls
  • WebApplications
  • IDS
  • Vulnerabilities
  • Email Clients
  • File Sharing
  • Spy / Ad Blockers
  • Web Browsers
  • Web Servers
  • Networking
  • Anti-Virus
  • Chat / IM
  • Anti Spam
Developer
  • Web Servers
  • Web Browsers
  • Game Programming
  • Dev Tools
  • Industry Specific
  • Office / Productivity
  • Database
  • CYGWIN
  • Web Development
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Programming
  • Content Management
  • Application Servers
  • Protocols
Storage
  • Removable Backup Media
  • Storage Technology
  • Servers
  • Grid
  • Remote Access
  • Backup / Restore
  • Misc
  • Hard Drives
OS
  • Miscellaneous
  • Security
  • Development
  • Linux
  • VMWare
  • MainFrame OS
  • Unix
  • Apple
  • OS / 2
  • AS / 400
  • BeOS
  • Microsoft
  • VMS / OpenVMS
Database
  • Oracle
  • Miscellaneous
  • MySQL
  • Software
  • Sybase
  • Contact Management
  • PostgreSQL
  • Data Manipulation
  • Clarion
  • InterSystems Cache
  • Siebel
  • MUMPS
  • OLAP
  • SQLBase
  • SAS
  • GIS & GPS
  • 4GL
  • Berkeley DB
  • DB2
  • Informix
  • Interbase / Firebird
  • FoxPro
  • Reporting
  • LDAP
  • Filemaker Pro
  • MS SQL Server
  • dBase
  • MS Access
Security
  • Misc
  • Web Browsers
  • Software Firewalls
  • Operating Systems Security
  • File Sharing
  • Spy / Ad Blockers
  • Vulnerabilities
  • WebApplications
  • IDS
  • Anti-Virus
  • Encryption
  • Anti Spam
  • Email Clients
  • VPN
  • Chat / IM
Programming
  • Editors IDEs
  • Installation
  • Handhelds / PDAs
  • Multimedia Programming
  • System / Kernel
  • Algorithms
  • Game
  • Signal Processing
  • Project Management
  • Open Source
  • Database
  • Misc
  • Languages
  • Processor Platforms
  • Theory
Web Development
  • Scripting
  • Blogs
  • Web Servers
  • Software
  • Search Engines
  • Web Graphics
  • Images
  • Internet Marketing
  • Images and Photos
  • Components
  • Document Imaging
  • Web Languages/Standards
  • Illustration
  • WebApplications
  • Fonts
  • WebTrends / Stats
  • Authoring
  • Digital Camera Software
  • Miscellaneous
Networking
  • Protocols
  • Apple Networking
  • Network Management
  • Message Queue
  • Application Servers
  • Content Management
  • File Servers
  • Email Servers
  • Misc
  • Java Editors & IDEs
  • Wireless
  • Networking Hardware
  • Backup / Restore
  • System Utilities
  • ISPs & Hosting
  • Web Servers
  • Storage Technology
  • Removable Backup Media
  • Servers
  • Broadband
  • Grid
  • OS / 2
  • Novell Netware
  • Unix Networking
  • Windows Networking
  • Security
  • Telecommunications
  • Operating Systems
  • Linux Networking
Other
  • Community Advisor
  • Lounge
  • Community Support
  • New Net Users
  • Philosophy / Religion
  • Math / Science
  • Miscellaneous
  • URLs
  • Expert Lounge
  • Politics
  • Puzzles / Riddles
Community Support
  • Suggestions
  • New to EE
  • New Topics
  • Community Advisor
  • CleanUp
  • Announcements
  • General
  • Feedback
  • Input
  • EE Bugs
 
05.08.2008 at 02:28PM PDT, ID: 21528638

Rank: Sage

One simple way is to create reservations in DHCP for the users you want to keep from accessing the internet. Set these reservations to use the DHCP defaults, except the gateway, and as a gateway assign a non existent IP address, i.e a wrong gateway. All network access is usable, but they cannot get outside the network. I assume you are using exchange, if this is the case the incorrect gateway will not affect mail delivery and receipt.
Creating DHCP reservations:
http://technet2.microsoft.com/windowsserver/en/library/690d8742-3f92-4eac-ba00-8e93feaafe861033.mspx?mfr=true
 
05.08.2008 at 02:54PM PDT, ID: 21528802
I think the solution proposed could be circumvented is the night-shift configured a static IP with the correct gateway.  Another solution would be to be to use multiple VLANs, 1 with access to internet and the other with no access.  If you have a limited amount of ports to control in the restricted areas, you could even configure the switch to only allow a specific MAC to connect to the port (so users can just plugin to a different port and hop on VLAN with access).

Another solution is to use a internet proxy which requires login for access to internet.  All users get directed to proxy, if they're authorized to surf they can login and access internet.  If you create individual logins, uses can't share login because they're accountable.
 
05.08.2008 at 03:00PM PDT, ID: 21528840

Rank: Sage

I said simple solution :-)
Regular users cannot reconfigure network adapters, but you are right other than that it can be circumvented.
 
05.08.2008 at 03:22PM PDT, ID: 21528956
Any password-protected methods wouldn't work, as the users are quite happy to share passwords (although they are not allowed to). Those particular workstations are located in an engineering workshop full of blue collar workers who would like nothing more than to spend the night shift surfing for porn.

The network uses a Billion 7404VGO firewall/router to access the internet. It has the ability to deny access to specified MAC addresses. That is one option.

I had hoped that there was a way to solve it using group policy, as I wanted to deny changes to desktops, etc using group policy at the same time that I was restricting internet access.
 
05.08.2008 at 05:30PM PDT, ID: 21529618

Rank: Sage

Using reservations requires no desktop access, you just do so in the server's DHCP management console.
If you really want to restrict access to the network adapter you can further prevent access with group policy.

However, blocking at the router using MAC address restrictions is another good way to go. They can still clone MAC addresses, but that requires a little more skill.
 
05.09.2008 at 06:47AM PDT, ID: 21532717
Blocking at the firewall via MAC might be the easiest way to do it.  The users would probably have a hard time trying to figure out why they're being blocked.  Most users don't even know PCs have MAC addresses, let alone think to change that.
 
05.09.2008 at 06:57AM PDT, ID: 21532822

Rank: Sage

The advantage of the DHCP reservation is it cannot be edited.
 
05.09.2008 at 07:06AM PDT, ID: 21532924
If the users have admin rights on the PC (like many are configured), the users can choose to set IP manually and copy the settings of a PC with internet access.  This would work if the user can't change his IP settings.
 
05.09.2008 at 07:18AM PDT, ID: 21533067

Rank: Sage

I would be surprised if night shift workers interested in porn have admin rights, but we have all seen where it is necessary :-)
If that were the case you can remove rights to manage the network adapter through group policy. However, unless you need to make it air tight, you are now into multiple steps and I agree the router option would be simpler.
 
05.09.2008 at 06:02PM PDT, ID: 21537436
In the interim, as there is no reason for any staff to access the Web after hours, I set the router to block all sites between 6pm and 6am. However, it would be nice to have a solution that addresses the individual workstations.
 
05.09.2008 at 06:16PM PDT, ID: 21537470

Rank: Sage

Both the MAC address solution, and the DHCP reservation issue would do that. Both are configured for each workstation.
 
 
20080236-EE-VQP-29 / EE_QW_EXPERT_20070906