Solved

Restrict application and internet access to a single workstation

Posted on 2010-11-21
12
556 Views
Last Modified: 2012-06-27
Hi Experts.

I was hoping for some advice for setting up a single public computer (in a children's orthodontic clinic) with access to one proprietary full-screen application (that requires internet access to one site).  The computer is basically dedicated to this application.

The computer is a HP 6000 Pro all-in-one running Windows 7 Pro (on a server 2008 domain).

In the past, I have tried a similar setup on a Dell touchscreen all-in-one PC running Arlington Kiosk Browser but the children were always able to 'sidestep' the in-built security measures.  We don't want them exiting the app and opening IE (for example).

There has been a suggestion of additionally restricting access by limiting things by DNS, but this is only a partial solution.

I know that I could script the application to open on login etc and create a restricted user on the domain, but I was hoping for some experienced folks to point me in the right direction.

Thanks everyone!
Aaron.
0
Comment
Question by:Aaronazz
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
  • +1
12 Comments
 

Assisted Solution

by:Aaronazz
Aaronazz earned 0 total points
ID: 34184456
I am going to try to create a new user on the server with limited permissions, script the app to load on login and limit access to the app only if I can work out how.  I've not needed to do much with group policy in the past.
0
 
LVL 66

Assisted Solution

by:johnb6767
johnb6767 earned 249 total points
ID: 34184562
Windows SteadyState
http://www.microsoft.com/windows/products/winfamily/sharedaccess/default.mspx

 I use the ADM templates to create a GPO to manage the same settings. They are included with theinstallation of this app.
Lock it down using GPO, amd assign it to this PC. Can disable most anything. You can specify what sites are allowed via the proxy in IE.
0
 
LVL 66

Assisted Solution

by:johnb6767
johnb6767 earned 249 total points
ID: 34184568
Oh, and yes, these similar features are already in GPO, but here they are all; included in a simple, easy to find location in a single ADM file....

Also, in the registry......

Change "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon", "Shell" value to your application.
In the same key, make sure that "AutoRestartShell" (DWORD) is also set to 0x1.....

That way, instead of a user's desktop, they get your app.....
0
Comparison of Amazon Drive, Google Drive, OneDrive

What is Best for Backup: Amazon Drive, Google Drive or MS OneDrive? In this free whitepaper we look at their performance, pricing, and platform availability to help you decide which cloud drive is right for your situation. Download and read the results of our testing for free!

 
LVL 7

Accepted Solution

by:
D_Vante earned 84 total points
ID: 34188091
I think if you create two batch files and put the first one in the startup folder or the login and have the second one, HomeScreen.bat, call your app.
  The first one will wait for the second batch file to finish, then it will restart the computer and start over again.  Endless loop unless you escape out of it.


First Batch file

start /wait cmd /C "c:\batch\HomeScreen.bat"

c:\shutdown -r -f

0
 
LVL 47

Assisted Solution

by:dlethe
dlethe earned 167 total points
ID: 34213735
Pretty much every router you can buy has a built-in firewall that can restrict traffic to machines with certain mac addresses in the NIC.  I would just do the work in the router.  
0
 
LVL 66

Assisted Solution

by:johnb6767
johnb6767 earned 249 total points
ID: 34245029
Any update?
0
 

Assisted Solution

by:Aaronazz
Aaronazz earned 0 total points
ID: 34245535
Sorry there hasn't been an update.  I am waiting for after hours access to the machine to try the suggestions.  Thanks everyone for the input, I'll let you know how I got with it.

Aaron.
0
 

Assisted Solution

by:Aaronazz
Aaronazz earned 0 total points
ID: 34462019
Sorry, no update yet.  I will post as soon as I can properly test.

Thanks again everyone.
0
 
LVL 47

Assisted Solution

by:dlethe
dlethe earned 167 total points
ID: 34739474
Well all experts gave correct and valid information, as there are many ways to attack the problem.  I say split points evenly between experts who spent their time to answer the question.   There really is nothing here to "test", all are straightforward.
0
 

Author Closing Comment

by:Aaronazz
ID: 34824304
Sorry, I'm still getting the hang of EE.  I asked the question when the issue was a higher priority, then the user requirements changed slightly delaying me from testing solutions.  Thanks for all who offered assistance.  I will use the suggestions, but I just can't put a time on it.
0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
On some Windows 7 (SP1) computers, Windows Update becomes super slow even the computer is reasonably fast.  There's one solution that seemed to have worked well for me (after trying a few other suggested solutions).
This Micro Tutorial will teach you how to change your appearance and customize your Windows 7 interface to your unique preference. This will be demonstrated using Windows 7 operating system.
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question