Solved

Restrict web usage on windows enterprises

Posted on 2014-02-27
3
169 Views
Last Modified: 2014-03-16
Greetings,
we have windows 7 desktops with a windows server 2008 R2 enterprise.
I want to know is how to establish a policy for a user group to be only able to surf websites within specified domains.

ie.  if I'm business1, I only want business1.com and business1.net and subdomain.business1.com available at a particular desktop.

Thanks
0
Comment
Question by:Evan Cutler
3 Comments
 
LVL 35

Expert Comment

by:Cris Hanna
ID: 39894499
There is nothing within Windows Server natively that let's you manage how users access the internet.  it would require either 3rd party software or higher end router/firewall
0
 
LVL 23

Accepted Solution

by:
Coralon earned 500 total points
ID: 39895294
The easiest "cheap" way to do this is a combinations of policies and DNS settings.  
If you set your DNS to be it's own root server (.) and don't provide any root forwarders and you control the only domains (business1.com, business1.net), then you can prevent them from easily being able to get to other places on the internet.

Add a Group Policy to lockdown the DNS settings to prevent them from going to a public DNS.  Now, this is going to affect your entire domain, and will prevent windows update from  working.  To get around that, you could set up a WSUS server in the domain.  For that one server, you would set a 2nd NIC to be on the internal network, and set the default gateway to go to the public internet.  

You can also:
Block DNS except from specific machines at the external firewall.  Then you can also block all of your outbound traffic at the firewall, except for specific domains & ip addresses, and protocols.  

Another thought on this:
You could use a group policy to set a false proxy server that doesn't exist, and then use the exceptions to bypass this false proxy.

But, the best way is to use a 3rd party software/proxy.  WebSense is a good choice, and I believe Barracuda provides a good one.  If you wanted to go the managed firewall route, NetworkBox is pretty good.

Coralon
0
 
LVL 9

Author Closing Comment

by:Evan Cutler
ID: 39933113
Thank you for the solution.
I'd like for you to have the points because I know your solution will work for some people.  Apparently my backbone did not have the necessities to enable what you suggest.  We are working on it, but the timeline for EE doesn't allow for that.  That being said, if I have further questions, I'll repost.

Thanks again.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Remote Apps is a feature in server 2008 which allows users to run applications off Remote Desktop Servers without having to log into them to run the applications.  The user can either have a desktop shortcut installed or go through the web portal to…
When you start your Windows 10 PC and got an "Operating system not found" error or just saw  "Auto repair for startup". After a while, you have entered a loop for Auto repair which does not fix anything and you will be in a  panic as all your work w…
This Micro Tutorial will teach you the basics of configuring your computer to improve its speed. It will also teach you how to disable programs that are running in the background simultaneously. This will be demonstrated using Windows 7 operating…
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now