How to stop internet access but still allow intranet access for students

Posted on 2005-04-06
Last Modified: 2010-04-10
I'm a network admin in a high school.  On occassion we have students who abuse internet privileges (no surprise) and the penalty is to lose computer access for a month.  We have a SonicWall in place.  Content Filter is set to not allow porn/nudity.  Everything else is allowed per school's request.  We do not use roaming/mandatory profiles, as we are a mixed environment with PCs and Macs so it really doesn't do much good.  I will be implementing it next year, though.  We use Internet Explorer and on the Macs we have Internet Explorer and Safari.  I have Windows 2K3 Servers only.

Teachers complain because students who are banned are no longer able to access their network folders and printers, etc.  So my question is this:  How to allow students to be able to access the network, but not the internet during their disciplinary phase?  Is there a way to do this through Win 2K3 Server?  Or does it have to be done at the firewall?  Because students do not always sit at the same place, banning with IP addresses does no good in the current setup.  It would have to be based on user name . . .

Any help would be greatly appreciated.  Teachers feeling bad for these students have resorted to logging in with their user name and password so the student can get access. . . What a great help that is for the discipline . . .

Question by:dmcwherter
    LVL 13

    Accepted Solution

    Without setting up additonal hardware like an ISA Server or a Linux Solutioun (which I use) you could make a Temporary OU for Banned Internet and apply a new group policy.  In that group policy set the Internet Explorer Browser to use a Proxy Server.  Set the proxy server to point to a non-exisitant address, therefore stopping the student from getting internet access
    LVL 16

    Expert Comment

    Sonicwall *should* be able to do it for you I think but I've never payed with user-based rules on Sonicwall so I don't know quite where to point you. Suggest you log a request on your MySonicwall account, I've always found them to be very helpful.  (provided, of cousre, your maintenance / support has not expired. :-)

    LVL 25

    Expert Comment

    what do you use as your content filter?  Any good internet filter/monitor should be synched with your usernames, so you should just be able to go into your internet filter/monitor and block internet access on a per user or a per group basis.  I worked at a k-12 school for a while and this was pretty common.
    LVL 6

    Expert Comment

    If you're using AD then 2hype's solution will work, so long as you also change the GP so that they can't change the Proxy settings themselves.  

    Author Comment

    I'm going to give the OU thing a try in the morning and will let you know how it turns out.  

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Overview This article describes how to silently install Adobe Reader on multiple workstations, customize the installation options (accept EULA, remove desktop shortcut etc) using the Adobe Customization Wizard and install Adobe Reader font packs an…
    PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
    Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now