Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Need to block websites without using SonicWall CFS

Posted on 2009-07-10
2
Medium Priority
?
3,650 Views
Last Modified: 2012-05-07
I have a pro 2040 enhanced. We are using CFS to block content on most computers, there are some computers where the CFS is way too restrictive for the users to do their job and those IP addresses are expempt from being blocked by CFS. But, it has become apparent that websites like facebook, myspace, craigslist, monster and few others need to be blocked. I was wondering if there is a way to create a rule to block access to these websites on the individual IP's that have been exempted from CFS from.
No Active Directory is being used here either, Noone is logging into a domain.

Or maybe there is a better way to go about doing this?

thanks
0
Comment
Question by:moletech
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 6

Expert Comment

by:KevinCovert
ID: 24828854
just use the hosts file, or the sonicwall has a blacklist (deny) where you can explicitly block sites/urls.

If you want to block from a handful of hosts, I would use the hosts file (kind of a pain to manage on any moderate scale) or if all PCs need blocked, I would look into using OpenDNS, its free and great.

Hope that helps

Here is some info on the hosts file and how you could use it.
http://www.mvps.org/winhelp2002/hosts.htm


KMC
0
 
LVL 13

Accepted Solution

by:
Ugo Mena earned 1000 total points
ID: 24831937
Based on a similar enhanced 2040 setup, we use a combination of the CFS, IPS signatures, and address objects to restrict access to a variety of sites and services, while still allowing owners and top level mgmt to use specific blocked sites and services. First set up address object(s) for your exempt users, this allows you to excluded (or included) them from accessing specific IPS signatures (ie. Facebook login, myspace, etc.) Then set the CFS settings to the least restrictive filtering setting needed for all users. Finally use the IPS signatures, time schedules, and address objects to granularly set or remove restrictions on your exempt group.

I would not use the CFS blacklist to keep users off of sites like facebook, it is much easier and more reliable to restrict access using the IPS signatures.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
This tutorial will teach you the special effect of super speed similar to the fictional character Wally West aka "The Flash" After Shake : http://www.videocopilot.net/presets/after_shake/ All lightning effects with instructions : http://www.mediaf…
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…
Suggested Courses

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question