Solved

Configure Firefox (or IE) to allow only certain specified sites

Posted on 2010-11-23
10
1,574 Views
Last Modified: 2013-12-08
Is there a way to configure Firefox (or IE) to allow only certain specified sites?  I know I can block certain sites, but I want to allow only a few sites and block everything else.  This will be done on our Citrix server so that any web browsing by any user with that browser (one or the other) on the Citrix server will be restricted.  Thanks.

~bruno71
0
Comment
Question by:bruno71
  • 4
  • 3
  • 2
  • +1
10 Comments
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 34200068
If you want to allow only a few sites, perhaps its better to try to do it by means of routing.
On Citrix only allow routes to those sites (by means of a logon script or equal).
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 34200101
And don't give them a default gateway (to the internet).
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 34205692
Use a fake Proxy, but allow the sites you want to bypass it......

Windows SteadyState installation extracts some .adm files, and one of them is to Block Internet Access....

Just install it on a test box, and grab the .adm files to import into a GPO.....

http://www.microsoft.com/windows/products/winfamily/sharedaccess/default.mspx

You can use the native policy as well, but I post this one, as thier might be other settigns youd like to use to lockdown the profiles.....

FYI, this is for IE.... I assume you could do similar in FF, but not sure on the exact steps....
0
 
LVL 37

Expert Comment

by:Bing CISM / CISSP
ID: 34210285
for IE, you may try Content Advisor, the built-in functionality to control web access.

HOW TO: Use the Internet Explorer 6 Content Advisor to Control Access to Web Sites in Internet Explorer
http://support.microsoft.com/kb/310401
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 34225429
Fyi, content advisor would have issues on sites with a lot of JavaScript. Tried to implement once on a JS intensive site, and had to get the address of every darn button... Not bad for simple sites though...
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 

Author Comment

by:bruno71
ID: 34242225
I've tried Content advisor before, but it's not quite as clean as I would like.

I don't want to lock down the entire Citrix server, but just one browser.  For instance, I want to lock down IE because it will be published to employee training terminals for access to just specific sites.  But I want to leave Firefox open for normal users who may have a link in an email to open, etc.

I don't care which is locked down and which is open.

~bruno71
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 34245151
IE is easier to lock down via GPO (Fake Proxy/Allowed websites listed to "bypass").....

Firefox would need to be scripted and deployed.....
0
 

Author Comment

by:bruno71
ID: 34248117
johnb6767,

Can you direct me to those specific GPO settings?  I've only done a little with GPO before and can get lost in the jungle of policies.  Thanks.

~bruno71
0
 
LVL 66

Accepted Solution

by:
johnb6767 earned 500 total points
ID: 34254849
http://www.esoft.com/support_docs/GroupPolicyEditor.pdf

Some good screenshots.... Just use a bogus proxy like 127.0.0.1, and make sure you add teh sites you want EXCLUDED in the right hand box.....
0
 

Author Comment

by:bruno71
ID: 34259862
Thanks John...that worked great.  It also affected Firefox, but in the Firefox settings I changed it from "Use system proxy settings"  to "No proxy".  It seems to be working.  Thanks again.

~bruno71
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Now-a-days, indirectly, postal services have been replaced by email services. Yes, whenever we hear the word "email" a lot of people only think of gmail. Some people still think that email and gmail are one and the same thing :-). Let's see some …
I annotated my article on ransomware somewhat extensively, but I keep adding new references and wanted to put a link to the reference library.  Despite all the reference tools I have on hand, it was not easy to find a way to do this easily. I finall…
Google currently has a new report that is in beta and coming soon to Webmaster Tool accounts. This Micro Tutorial will highlight new features for Google Webmaster Tools.
Shows how to create a shortcut to site-search Experts Exchange using Google in the Chrome browser. This eliminates the need to type out site:experts-exchange.com whenever you want to search the site. Launch the Search Engine Menu: In chrome, via you…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now