Solved

Restrict application and internet access to a single workstation

Posted on 2010-11-21
12
552 Views
Last Modified: 2012-06-27
Hi Experts.

I was hoping for some advice for setting up a single public computer (in a children's orthodontic clinic) with access to one proprietary full-screen application (that requires internet access to one site).  The computer is basically dedicated to this application.

The computer is a HP 6000 Pro all-in-one running Windows 7 Pro (on a server 2008 domain).

In the past, I have tried a similar setup on a Dell touchscreen all-in-one PC running Arlington Kiosk Browser but the children were always able to 'sidestep' the in-built security measures.  We don't want them exiting the app and opening IE (for example).

There has been a suggestion of additionally restricting access by limiting things by DNS, but this is only a partial solution.

I know that I could script the application to open on login etc and create a restricted user on the domain, but I was hoping for some experienced folks to point me in the right direction.

Thanks everyone!
Aaron.
0
Comment
Question by:Aaronazz
  • 4
  • 3
  • 2
  • +1
12 Comments
 

Assisted Solution

by:Aaronazz
Aaronazz earned 0 total points
ID: 34184456
I am going to try to create a new user on the server with limited permissions, script the app to load on login and limit access to the app only if I can work out how.  I've not needed to do much with group policy in the past.
0
 
LVL 66

Assisted Solution

by:johnb6767
johnb6767 earned 249 total points
ID: 34184562
Windows SteadyState
http://www.microsoft.com/windows/products/winfamily/sharedaccess/default.mspx

 I use the ADM templates to create a GPO to manage the same settings. They are included with theinstallation of this app.
Lock it down using GPO, amd assign it to this PC. Can disable most anything. You can specify what sites are allowed via the proxy in IE.
0
 
LVL 66

Assisted Solution

by:johnb6767
johnb6767 earned 249 total points
ID: 34184568
Oh, and yes, these similar features are already in GPO, but here they are all; included in a simple, easy to find location in a single ADM file....

Also, in the registry......

Change "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon", "Shell" value to your application.
In the same key, make sure that "AutoRestartShell" (DWORD) is also set to 0x1.....

That way, instead of a user's desktop, they get your app.....
0
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

 
LVL 7

Accepted Solution

by:
D_Vante earned 84 total points
ID: 34188091
I think if you create two batch files and put the first one in the startup folder or the login and have the second one, HomeScreen.bat, call your app.
  The first one will wait for the second batch file to finish, then it will restart the computer and start over again.  Endless loop unless you escape out of it.


First Batch file

start /wait cmd /C "c:\batch\HomeScreen.bat"

c:\shutdown -r -f

0
 
LVL 47

Assisted Solution

by:dlethe
dlethe earned 167 total points
ID: 34213735
Pretty much every router you can buy has a built-in firewall that can restrict traffic to machines with certain mac addresses in the NIC.  I would just do the work in the router.  
0
 
LVL 66

Assisted Solution

by:johnb6767
johnb6767 earned 249 total points
ID: 34245029
Any update?
0
 

Assisted Solution

by:Aaronazz
Aaronazz earned 0 total points
ID: 34245535
Sorry there hasn't been an update.  I am waiting for after hours access to the machine to try the suggestions.  Thanks everyone for the input, I'll let you know how I got with it.

Aaron.
0
 

Assisted Solution

by:Aaronazz
Aaronazz earned 0 total points
ID: 34462019
Sorry, no update yet.  I will post as soon as I can properly test.

Thanks again everyone.
0
 
LVL 47

Assisted Solution

by:dlethe
dlethe earned 167 total points
ID: 34739474
Well all experts gave correct and valid information, as there are many ways to attack the problem.  I say split points evenly between experts who spent their time to answer the question.   There really is nothing here to "test", all are straightforward.
0
 

Author Closing Comment

by:Aaronazz
ID: 34824304
Sorry, I'm still getting the hang of EE.  I asked the question when the issue was a higher priority, then the user requirements changed slightly delaying me from testing solutions.  Thanks for all who offered assistance.  I will use the suggestions, but I just can't put a time on it.
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Active Directory Failed Logon Attempts. 18 52
Export a GPO and import a GPO 3 43
Windows Password recovery 7 35
Server Rebuild after 2 drive in raid crashed 16 41
By default the complete memory dump option is disabled in windows . If we want to enable the complete memory dump for a diagnostic purpose, we have a solution for it. here we are using the registry method to enable this.
On some Windows 7 (SP1) computers, Windows Update becomes super slow even the computer is reasonably fast.  There's one solution that seemed to have worked well for me (after trying a few other suggested solutions).
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question