• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1727
  • Last Modified:

Blocking Web Site Access

We are looking into the options for blocking access to certain web sites from our LAN.
Server 2003 Sp1.
As near as I can tell there is no way to set this up within 2003. Is this correct?

Our ServGate firewall doesn't seem to have any options in this area but the manual is gone...as are they, it seems.

what are our options?
I have seen a 3rd party proxy application from Wavecrest called Cyblock that might be worth something but I need some input.




0
Al Jee
Asked:
Al Jee
6 Solutions
 
LauraEHunterMVPCommented:
The built-in means to do this in 2003/Active Directory is not very manageable/scalable; it involves using Content Advisor settings in Internet Explorer: http://support.microsoft.com/kb/310401

For a more scalable alternative you'll need to look at third-party products, either software-based like ISA server or else an Internet security appliance from any number of vendors.
0
 
Brian PiercePhotographerCommented:
You can do some stuff with the security features in XP/2003 eg http://www.wikihow.com/Block-a-Website-in-Internet-Explorer

but if you want to do this properly you will have to use a proxy server. These vary in features and price from ISA server http://www.microsoft.com/isaserver/default.mspx to acFreeProxy http://sourceforge.net/projects/acfreeproxy/

0
 
Netman66Commented:
Or WinProxy.  A cheaper alternative to ISA (not nearly as Enterprise either) but it works well for the price.

Content Advisor works well is the sites are Rated.  If not, then the site is blocked unless you check the box to allow unrated sites (which IMHO kind of defeats the purpose).

Another method is to employ a HOSTS file that points these sites to the local loopback address.  Use a Startup script to copy the new file after each update.  You'll find this in \Windows\System32\Drivers\etc.
0
Firewall Management 201 with Professor Wool

In this whiteboard video, Professor Wool highlights the challenges, benefits and trade-offs of utilizing zero-touch automation for security policy change management. Watch and Learn!

 
Jeffrey Kane - TechSoEasyPrincipal ConsultantCommented:
StoneG,

You might find this interesting: http:Q_22644344.html, but it's actually a solution to limit ALL but a FEW instead of the other way around.

Depending on the size of your network, there are other ways to just block specific sites as well.  For instance on a smaller network, most smaller routers have web filtering capabilities.


Jeff
TechSoEasy
0
 
Tom-J-LaelCommented:
This is what I've done in the past. it's a semi interesting approach IMHO...

*IF* you use an internal DNS server:


Create Foward lookup zones for domains you want to block and leave those zones empty.

**Please Note**

This is not going to prevent users from changing what DNS servers they point their machines to.

It's not going to prevent users from using open proxies. You'll need third party software or proxy service for that.

but, I'd like to believe the average user won't put that much effort into trying to browse myspace or whatever...
0
 
wingateslCommented:
You can install a trial of Surfcontrol Web Filter from www.surfcontrol.com
When the trial expires it will still block the websites you are after.
0
 
Al JeeAuthor Commented:
Thanks for the input everybody.

I'll look at what has been presented ^ and get back in a few days.
0
 
Al JeeAuthor Commented:
Passing this problem back to the [ahem] who proposed it because [ahem] is po'd at a VP.

[heh heh]


Thanks for the participation & the good info!
0
 
Al JeeAuthor Commented:
{stupid option}  what the point of the "additional comments" when selecting the answer & point distribution if they don't show up here?   {stupid option }

Again:

I'm passing this back to [ahem] who proposed this just because [ahem] is po'd at a VP.

[heh heh]



Thanks for the good information, all.
I'm sure it will come in handy in the future.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Increase Security & Decrease Risk with NSPM Tools

Analyst firm, Enterprise Management Associates (EMA) reveals significant benefits to enterprises when using Network Security Policy Management (NSPM) solutions, while organizations without, experienced issues including non standard security policies and failed cloud migrations

Tackle projects and never again get stuck behind a technical roadblock.
Join Now