Sorry for the delay and THANKS for the resolution!
Main Topics
Browse All TopicsI am working with a Firebox X700 and dont have any experience with these. My boss wants the following:
1. Limit browsing on about 10 specific computers to about 10 specific sites. Meaning, they cant browse any site except for about 10 specified sites
2. Block instant messaging for those 10 computers
Is this doable? And if so, could you explain how?
Thanks in advance!
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: dpk_walPosted on 2008-05-19 at 21:58:38ID: 21603580
In Policy manager create a service which would allow outbound HTTP connections from these machine only to those ten sites, configure the service as below: 0; to website-public-ip1,2,3...1 0
0; to ANY
HTTP
Incoming "Disabled"
Outgoing "Enabled and Allowed"; from client-machine-ip1,2,3...1
Here you should have static IP addresses on the machines; if not then this solution would not work. Also, the website addresses are also constant [you might need to manually update the IP addresses if there are any changes].
For dynamic IP address on clients, you would need to configure authentication, where the users would be first authenticated through firebox/AD/LDAP/RADIUS server etc., and then would be allowed access to internet. However, drawback of this solution is authentication would be implemented for all the users.
For blocking instant messaging, you can further create ANY [from packet filter] service as below:
ANY-block
Incoming "Disabled"
Outgoing "Enabled and Denied"; from client-machine-ip1,2,3...1
Please remember these users would now be only able to access only the 10 websites and nothing else.
Also, remember if you are using version 8.3.1 or higher of WG software that you put the HTTP service up in order before the ANY-block service.
Please let know if you need more details.
Thank you.