Solved

Restrict access to internet for some users

Posted on 2004-04-08
3
241 Views
Last Modified: 2010-04-19
Hi there,

I am setting up a new server for a client together with an ADSL connection for about 10 desktops. My client does not trust their staff and so does not want everyone to be able to access the internet. However, the client does want everyone to have email.

I was thinking of restrivting Inet access by using a proxy such as squid and closing of all access to port 80 except for the proxy. I can then use the proxy config to allow certain machines access to the web. However, I would like to a set up where I can deny specific users regardless of the machine they are using.
Any ideas how I can do this or comments on my initial thoughts?

Cheers

Richard

0
Comment
Question by:greenanr
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 20

Accepted Solution

by:
What90 earned 250 total points
ID: 10788837
If it's a windows network you may look at using Ms ISA server. It's a firewall/proxy which can integrate with Ms or Active DIrectory and work on rules based on users and groups.

http://www.microsoft.com/isaserver/
http://www.isaserver.org/ 
0
 

Author Comment

by:greenanr
ID: 10790404
This is a good solution (and you get the points :-) ). However, I was really looking for an alternative that doesn't cost $2K. Does anyone know of such and alternative.


Cheers

Richard
0
 

Author Comment

by:greenanr
ID: 11021545
Hi there,

To answer my own question:

I set up a Windows 2003 Server as a multihomed system. One NIC I connected to the ADSL router and the other I connected to the rest of the network. I then used Windows RRAS to filter the inbound ports to only allow email ports through.
Finally I set up Squid as a proxy and used access control lists to stop proxy access to certain users.

Job done :-)

Richard
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Add user group members to local Administrators 2 62
Moving RDP Server to New Server. 3 78
Want Win 10 Pro to search like Server 2010 or 2012 27 156
Time server on domain 3 62
Scenerio: You have a server running Server 2003 and have applied a retail pack of Terminal Server Licenses.  You want to change servers or your server has crashed and you need to reapply the Terminal Server Licenses. When you enter the 16-digit lic…
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question