?
Solved

How to filter certain workstations or laptops from accessing Internet in WIN 2000 Server?

Posted on 2006-07-11
11
Medium Priority
?
303 Views
Last Modified: 2012-05-05
I have a WIN 2000 Server with ADSL through a lnksys router that my clients have access to the internet.  I want certain PC's and laptop who log unto the server as a user to not have access to the internet.  Or should I do this through the LINKSYS Router?  Any help is appreciated.
0
Comment
Question by:scatcom
  • 5
  • 3
  • 2
  • +1
11 Comments
 
LVL 104

Expert Comment

by:Sembee
ID: 17084620
Do you want to stop anyone who uses certain machines from accessing the internet?
Or certain users on any machines?

If anyone on certain machines then the easiest way is to reserve an IP address in DHCP and then don't set a default gateway for that machine.

If for certain users, then use a group policy to set dummy proxy settings in Internet Explorer.
Will not stop someone using firefox on their machine - if they can install it.

Otherwise you need something where access can be authenticated - a proxy of some kind. I don't think any of the Linksys routers have that capability, so it would have to be a third party product.

Simon.
0
 

Author Comment

by:scatcom
ID: 17085489
DCHP (Server right?) and don't set the default gateway to the router itself? or gateway to the ISP settings?
0
 
LVL 104

Expert Comment

by:Sembee
ID: 17085617
If you operating in a domain, then the DHCP server should be a Windows 2000 machine. If you are using a router as the DHCP server then you don't have the control over the DHCP that you need.

Don't set any default gateway - so that the machines only get an IP address, subnet mask and DNS server.

Simon.
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 

Author Comment

by:scatcom
ID: 17086076
I'll give that a try and see if it works.......
0
 
LVL 12

Expert Comment

by:Einstine98
ID: 17087145
ISA server would be ideal for this kind of job, but i you can afford it
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17087321
if you are going to take the route of not setting a gateway, then block users manually entering one...! 99% of the time the gateway is the .1 address and it doesnt take a genius to know how to insert an address...i like the false proxy idea myself, thats what i use then block them changing it :)
0
 

Author Comment

by:scatcom
ID: 17095500
So do I block the users in the router or in the server?
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17095510
via the server with group policy
0
 

Author Comment

by:scatcom
ID: 17095538
Create group policy first and then add users to this policy?  And if so, how do I construct this policy specifically to a false proxy scheme? thanks!!
0
 
LVL 48

Accepted Solution

by:
Jay_Jay70 earned 500 total points
ID: 17095560
create a seperate group policy with this false proxy

User Configuration\Windows Settings\Internet Explorer Maintenance\Connection:

then stop the changes

Administrative Templates\Windows Components\Internet Explorer\Disable changing proxy settings

add this policy to your desired OU and use securitly filtering to get rid of the users you DONT want it applied to

http://www.windowsnetworking.com/articles_tutorials/Group-Policy-Security-Filtering.html
0
 

Author Comment

by:scatcom
ID: 17095574
Thanks everyone....
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Need In an Active Directory enviroment, the PDC emulator provide time synchronization for the domain. This is important since Active Directory uses Kerberos for authentication.  By default, if the time difference between systems is off by more …
This is the first one of a series of articles I’ll be writing to address technical issues that are always referred to as network problems. The network boundaries have changed, therefore having an understanding of how each piece in the network  puzzl…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Is your OST file inaccessible, Need to transfer OST file from one computer to another? Want to convert OST file to PST? If the answer to any of the above question is yes, then look no further. With the help of Stellar OST to PST Converter, you can e…

615 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question