Whats the best way to block access to specific sites?

I work in an environment where we have public access to our information.  This information can be viewed and researched any time for free.  However paper and digital copies of the information to be taken away must be paid for.  Recently the honor system seems to have fallen down as some researchers have been emailing themselves gigabytes of data from our research computers.

Time to restrict access.

Points to note:  I don't control the DNS; the OU that these computers reside in is the ONLY one that should be restricted; there are legitimate reasons to be accessing the internet from our research computers, so we just want to block access to web mail; the solution needs to work for both IE and Firefox, on a mixture of Vista and Win 7 computers.

So far in my research, the hosts file seems to be the 'best' solution, but it's clunky, inflexible and wont accept wild cards.
Williams Co IT DeptAsked:
Who is Participating?
 
Williams Co IT DeptConnect With a Mentor Author Commented:
OK IPSec seems to have resolved the issue!!

A Group Policy Object able to be applied to a single OU, using existing infrastructure, blocking all secure connections on port 443.  This will block some possibly legitimate uses of the internet on those machines, but they will be few and there are other options for the public if they need that.

GPO
Computer Configuration>
Policies>
Windows Settings>
Security Settings>
IP Security Policies>
Created a new IP Security Policy, followed Wizard and added rules for LAN connections that connect through TCP and UDP to port 443.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.