We have several group homes that have TZ170s. Staff are connected to LAN, with manual entries as content filtering. We need to connect the residents (kids) of these group homes to the TZ170 and have them be protected through Content Filtering Subscription (which we will get).
The OPT has already been configured for a different subnet in NAT Mode. Connectivity is fine through SonicWall, and any existing CF policies that exist get applied to the OPT zone PC.
Problems:
Access to sites from OPT zone does not show up in the Report Log (Web Site Hits, Bandwidth, etc). Only the LAN zone appears in those hits. This does not allow us to have the ability to see what sites the OPT zone PC accesses in order to know which sites to add to block list. However, the sites that do get blocked on both zones appear in the general log.
When purchasing Premium Content Filtering Service, it will be applied to both zones....problem with that is, staff (LAN) may need to access content while residents (OPT) cannot. I still need to block certain sites for both zones, just be more lenient on staff (LAN) Basically, I need two different policies for both interfaces, but it doesn't appear sonicwall has the ability to do that.
My thoughts/requests:
Need a solution that will allow seperate content filtering policies for OPT zone and LAN zones.
Need to be able to see which sites are being accessed/blocked on both
Avoid purchasing additional expensive appliance
Is there a way to perhaps point the OPT zone PCs (I'd configure it through local policy) to proxy into a web-based proxy filter, that is cheap? Should I implement ISA server for the OPT computers, and just have those point to ISA server for policies? That way I would only need to worry about the 15 or so computer licenses that are spread throughout 8 sites.
Implement local software for those PCs (netnanny type)..problem with that is, since PCs are on different network, I can't remote connect into them through sonicwall using VNC. (All sonicwalls have VPN to main site where I'm at).
Any other ideas/thoughts welcome. Thanks in advance!
Start Free Trial