Internet blocking

V

Vlaad

Hi,
I have, hopefully, a simple question.
I have a site that has approx 85 users.
All are using WinXP and Win2k workstations in a fully
functional AD environment.
These users are in different departments.
Some departments are allowed Internet access and some are
not.

What is the BEST group policy to use in order to fulfill
this need?

Earlier I tried to give a bad proxy address to those that
should not have access (And, of course, hid their
connection tab). This worked fine except when some users
that were working with Outlook (We do have an exchange
2000 server). In some cases when users tried to reply to
some e-mails it appeared that Outlook would freeze for a
few minutes before sending the e-mail. I believe this was
due to the system trying to locate a web-based object. I
saw this a lot with web-based photographs.

I don't need to kill access to the web; I just need to
quell surfing ability to the web.

Any thoughts on this would be very helpful,

Thanks,
Vlaad
 
S

Steven L Umbach

If the departments have their computers in different Organizational Units, you can
implement ipsec filtering policy for each OU or at least to the OU's that do not need
internet access. Ipsec policies apply to computers. You can create an ipsec policy
that uses just block and permit filter actions. You start with a block all IP traffic
mirrored rule, add a permit all lan traffic mirrored rule based on subnet and then
create the exceptions [if any] for permitted outbound access mirrored rules. See the
links below for examples. --- Steve

http://www.microsoft.com/windows2000/techinfo/planning/security/ipsecsteps.asp
http://www.securityfocus.com/infocus/1559
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top