Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

How to white-list internal only web access?  Block external web surfing and filter pages.

Posted on 2011-09-29
6
Medium Priority
?
695 Views
Last Modified: 2012-05-12
We have a few machines running Win XP SP3 and Win 7 that we'd like to limit web surfing on.  
How can we best implement this?

REQUIREMENTS:

----------------------------------------------------------------------------------------------------------------------------------
Block Web:    We want to block all other external web-surfing.
Access Internal:   We need to make internally served pages available they are all on one domain.
GPO:     We'd like to apply any solution by policy applied to a single OU.
0
Comment
Question by:ServDeskKnows
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 2

Assisted Solution

by:GoatCreek
GoatCreek earned 300 total points
ID: 36814259
Set the proxy server to 127.0.0.1, bypass proxy for local adresses, add the local network to bypass the proxy server.
0
 

Author Comment

by:ServDeskKnows
ID: 36814271
GoatCreek: I can't use the local proxy.  

That's what we've been doing, but a Citrix client application isn't able to cope with that proxy setting.  I'm looking for an alternative to that exact setup.
0
 
LVL 8

Accepted Solution

by:
MarkieS earned 900 total points
ID: 36814447
Can you utilise something like PAC files or WPAD browser settings.

A PAC file or WPAD.dat like below can be used to direct and/or restrict Web browsing

function FindProxyForURL(url, host) {

// If URL has no dots in domain name, send direct.
      if (isPlainHostName(host))
            return "DIRECT";

// If URL matches, send direct.
      if (shExpMatch(url,"*domain123.com/folder/*") ||
          shExpMatch(url,"*domainXYZ.com:*/*"))                  
            return "DIRECT";


// If hostname matches, send direct.
      if (dnsDomainIs(host, "vpn.domain.com") ||
            dnsDomainIs(host, "abcdomain.com"))
            return "DIRECT";

// If hostname resolves to internal IP, send direct.
      var resolved_ip = dnsResolve(host);
      if (isInNet(resolved_ip, "10.0.0.0", "255.0.0.0") ||
            isInNet(resolved_ip, "172.16.0.0",  "255.240.0.0") ||
          isInNet(resolved_ip, "192.168.0.0", "255.255.0.0") ||
          isInNet(resolved_ip, "127.0.0.0", "255.255.255.0"))
            return "DIRECT";

// DEFAULT RULE: All other traffic, use below proxies, in fail-over order.
      return "PROXY PROXYSERVERNAME1:8080; PROXY PROXYSERVERNAME2:8080; DIRECT";

0
Prepare for your VMware VCP6-DCV exam.

Josh Coen and Jason Langer have prepared the latest edition of VCP study guide. Both authors have been working in the IT field for more than a decade, and both hold VMware certifications. This 163-page guide covers all 10 of the exam blueprint sections.

 
LVL 2

Assisted Solution

by:GoatCreek
GoatCreek earned 300 total points
ID: 36895578
You can set the proxy settings also by AD policy
0
 
LVL 29

Assisted Solution

by:pwindell
pwindell earned 300 total points
ID: 36986622
It is no where near as complex and it is being made here.

You just set the Firewall/Proxy to just not allow certain machines to the Internet.  That's it,...Done.

Internal browsing does not go through the proxy in the first pace,..so that is irrelevant.  The whole point of a LAT (Local Address Table) on a firewall/proxy is to define the interior LAN so that the Firewall/Proxy already ignores request sent to any such destination,...so there is nothing "extra" that you have to do there.
0
 

Author Closing Comment

by:ServDeskKnows
ID: 37603638
Proxy works, but I was trying to avoid it.

Extra points to PAC files and a nod to Firewall configuration.
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Configuring network clients can be a chore, especially if there are a large number of them or a lot of itinerant users.  DHCP dynamically manages this process, much to the relief of users and administrators alike!
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Viewers will learn how to properly install and use Secure Shell (SSH) to work on projects or homework remotely. Download Secure Shell: Follow basic installation instructions: Open Secure Shell and use "Quick Connect" to enter credentials includi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question