Re: Internet Access Restriction using Group Policy - Anyone know how?

From: Karl Levinson, mvp (levinson_k_at_despammed.com)
Date: 12/31/04


Date: Fri, 31 Dec 2004 07:44:32 -0500


"BobRosas" <BobRosas@discussions.microsoft.com> wrote in message
news:71D563C2-9491-4F24-802B-1DF74EDAB34E@microsoft.com...
> I want to restrict internet access through a GPO. Can this be done?

I feel this is much better done first via a router, firewall or a proxy
server, preferably one that can do per-user authentication. I believe
www.netscreen.com has relatively inexpensive firewalls starting around $550
US, or cheaper on ebay, that can do this. Once you've done that, if you
want to use some method to cripple Internet access via GP, that might not be
such a bad idea in addition to using your firewall. One problem is that
your GP does nothing for computers that are not in the domain, such as a
laptop that enters your environment.

Additionally, if your network is all on one subnet, you could possibly
configure your DHCP server using reservations to not give out a default
gateway IP address to certain MAC addresses. This doesn't do anything for
people that put in a static IP address, or people that switch network cards
or choose to spoof their MAC address.

regards,

Karl Levinson, MS MVP, CISSP
Microsoft Security FAQ:
   http://securityadmin.info



Relevant Pages

  • Re: SNAT
    ... NATing could cause any problems with outbound/inbound internet access. ... Get rid of your external NAT box. ... Choose the upcoming ISA2K4 as your firewall solution. ... computers you have to make them either firewall or webproxy client. ...
    (microsoft.public.isa)
  • Re: Disable Internet Explorer
    ... The best solution is to use a firewall that can ... can not access the proxy settings via Group Policy or registry mod. ... do that- or at least the same result of disallowing internet access ... Shouldn't the enforcement option allow the runas? ...
    (microsoft.public.windowsxp.security_admin)
  • Re: message 0x80072EFD
    ... This is how I set Norton firewall so I can download updates and keep the ... in resulting dialog box, under Program Internet Access, scroll down to Microsoft Generic Host Process for win32 services. ... Computers: Only the computers and sites listed below - ... Generic Host Proc - Windows Update 5 (or call it anything else ...
    (microsoft.public.windowsupdate)
  • Re: Tool to find hidden web proxy server
    ... >> This problem is strictly with in company internet access firewall and in the ... policy for Internet access says it is through IP ... >> default ports and distributed the internet access to their friends. ... admin & senior security consultant: ...
    (Pen-Test)
  • Re: Use XP Firewall with Router & Firewall?
    ... > easily cut off all internet access, ... > the XP firewall to block outbound traffic is zero-it doesn't attempt it. ... there are better tools instead of a PFW. ... control get something that controls applications and prevents software ...
    (comp.security.firewalls)