Solved

Block websites but still allow for some users

Posted on 2011-09-22
7
325 Views
Last Modified: 2012-12-16
Hello,

I'm currently helping a company that got following issue:
Their needs are to block sites like youtube.com/facebook.com etc anything not work related.

That is currently done by redirecting the website on the Domain Controllers DNS, so the users can't do domain lookups.
 
The problem is that some users need to get access to some of those websites.

The current solutions that is done is with changing the dns on the users PC to googleDNS.
But that leaves problems when the users need to sync up to the AD.(note the company currently only has one DC)

I have tried with creating hosts file on the PC while using google dns
eg
10.8.8.2   dc00.company.local
But still when doing nslookup to dc00/dc00.company.local or 10.8.8.2 it wont look up in the hosts file before it looks in google dns.

Anyone have idea what a possible solutions could be?
0
Comment
Question by:Infolink_Denmark
7 Comments
 
LVL 39

Assisted Solution

by:Krzysztof Pytko
Krzysztof Pytko earned 125 total points
ID: 36578911
The most simple way is to use local hosts file on each worksatation :) File is located in %WINDIR%\SYSTEM32\Drivers\Etc

put there lines in this format

www.facebook.com 127.0.0.1
www.youtube.com 127.0.0.1

and they won't be able to access those pages :) It's a littlee bit work but it can be scripted or used by GPO

Another way is to set up PROXY server based on example on SQUID and configure access rules for user groups.

Regards,
Krzysztof
0
 
LVL 12

Expert Comment

by:Alan3285
ID: 36579050
Hi,

If you want to block those sites on some *machines* then you could setup the HOSTS files on those machines by putting in entries such as:

127.0.0.1    www.youtube.com

However, note that doing so will block those sites for ALL USERS on those machines.

Alternatively, you could use some dedicated software on the server and / or gateway that would offer more granularity.

If most users are matched to, and use, only one machine, then the HOSTS file solution could be easiest, especially if the total number of machines is not to great (20 would be manageable, 200 would be too much of a pain).

HTH,

Alan.
0
 

Author Comment

by:Infolink_Denmark
ID: 36579780
There is about 80-100 users and 10 of them need access to it.
I'm currently thinking of using eg Internet Explorer with a proxy setting and then just tell them to only use that browser to access the websites
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Author Comment

by:Infolink_Denmark
ID: 36579796
To Alan3285:

It's the other way around i need to allow it on some "machines" but for all the others it need to blocked
0
 
LVL 12

Accepted Solution

by:
Alan3285 earned 125 total points
ID: 36583464
H Infolink_Denmark,

Same answer (if you go that way).  You set the HOSTS file on the 90 machines that are blocked, and leave it blank (default) on the 10 machines that you want to allow to reach those sites.

You mention using a proxy.  That would work, and if you set up a proxy with authentication and rules, you could make all the machines point there, and handle things at a user level which seems a better solution, but more complicated to set up.

Alan.
0
 
LVL 26

Expert Comment

by:Pber
ID: 38695551
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Synchronize a new Active Directory domain with an existing Office 365 tenant
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question