Restricting Viewable Websites for group in Windows 2003 domain

I have been tasked with restricting the websites viewable for a small group of employees.  They only need to be able to see 3-4 sites related to work.  I know I can create a proxy server, but for a group this small I'd rather do it via group policy or content restrictions.

I added all the sites as approved in content advisor.  I have been unable to find a GP to block all sites not approved.

I also looked into the security zones, but didn't see anyway to block the internet and view only the trusted sites.

Suggestions?
keproAsked:
Who is Participating?
 
rsivanandanConnect With a Mentor Commented:
Well, that will be too much :-) You can achieve that kind of granularity only through a commercial product;

www.websense.com

www.surfcontrol.com

www.n2h2.com

squid on linux etc...

For details on websense, look at one of my previous posts.

http://www.experts-exchange.com/Security/Win_Security/Q_21910905.html

Cheers,
Rajesh
0
 
rsivanandanCommented:
Simple solution would be to deal with DNS.

Remove DNS from all those machines for the 'small' group.

For these 3 or 4 sites, add dns entries in the 'hosts' file.

So they will be able to launch those sites while the other sites will timeout because of dns resolution.

Quick and neat.

Cheers,
Rajesh
0
 
keproAuthor Commented:
Hmm I was thinking more along the lines of content advisor.  I've added all the sites.  Is there a way to prevent all sites not approved from being visited?
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.