Anyone experienced this at work?
Care to tell how they did it?

I want to implement such feature too,i'm aware of IP/Domain filtering via router,but i seek alternative options before i opt for one.

Update 1:

Allrighty,i'll be checking some things u guys recommended and will post results.
Thanks to all

update 2:
Quick update:
Went ahead and tried Untangle first,looked most user friendly.
Installed it onto PC,but run into the issue of not detecting network cards.
Read about it,looks like a PC i took for gateway is too old.
Will see to use another PC/buy network card/try installing drivers tomorrow.

10 years ago*

Comment has been collapsed.

Set up a caching proxy (like squid), set all the computers to connect to internet through the proxy. Have the firewall block access to internet except via the proxy. Configure the proxy server to allow/deny what you want.

Another possibility is the security software (antivirus, automatic encryption, etc) you run might have options to allow/deny certain sites.

10 years ago
Permalink

Comment has been collapsed.

at this moment,my company's got about 20,30 PC's,laptops included in there.
An option where i would mess with each of those PC's individually is not that great for me,especially in case of some corrections later on.

A internet is set up in such way that main router sends singal into switch,which then divides signal across the company.
By the looks of it,cleanest solution would be controling the traffic right there at the main router point.

10 years ago
Permalink

Comment has been collapsed.

This would be the easiest way, in that you wouldn't have to leave your chair.

For 5 of out 30 PCs where I work I set up the people's Internet Explorer to run through a false proxy. I then removed the Connections Tab from the Internet Options menu using the registry so they can't remove the proxy. Has worked like a charm and even if the computer receives a new IP address for whatever reason it still blocks it. The only way for them to get around it would be to download chrome or something from home, put it on a USB, and hook it up and install.

10 years ago
Permalink

Comment has been collapsed.

But not for the Boss himself!?
He needs access to the net for gambling points on Steamgifts.com!

10 years ago
Permalink

Comment has been collapsed.

That won't work depending on what they are doing as DNS lookups won't normally go through the proxy itself.

10 years ago
Permalink

Comment has been collapsed.

I think it will. I've been in an environment like that before. Local DNS return nothing. nslookup won't work but if you set proxy in browser, it will resolve name just fine. Here

10 years ago
Permalink

Comment has been collapsed.

Remove internet explorer shortcut from desktop/taskbar

10 years ago
Permalink

Comment has been collapsed.

Great solution.

10 years ago
Permalink

Comment has been collapsed.

^this!

10 years ago
Permalink

Comment has been collapsed.

I did this on our clock-in computers and people just found new ways to get it to open.

10 years ago
Permalink

Comment has been collapsed.

You should walk stealthily around the office and punch people real hard if they are browsing Internetz instead of doing the job. This is the way it's done in major IT companies such as Google, IBM and Pornhub.

10 years ago
Permalink

Comment has been collapsed.

^

10 years ago
Permalink

Comment has been collapsed.

you is funy gai, i liek u

10 years ago
Permalink

Comment has been collapsed.

Employ an IT worker to do this for you or you might bungle something up if you're not IT-savvy like my dad, or alternatively get a smart-ass teenager who does IT (Cheaper, but riskier. He might install other bs.)

10 years ago
Permalink

Comment has been collapsed.

Very easy. I'm using Mikrotik Router - it's a simple PC with weak power with custom HDD made by Mikrotik. Been working flawlessly with Simple Queue and Web Proxy.

10 years ago
Permalink

Comment has been collapsed.

I'll check on tuesday if there's a possibility of ordering those in my country

10 years ago
Permalink

Comment has been collapsed.

Not the best solution when they could just type a URL into Windows Explorer and still get IE to open…

10 years ago
Permalink

Comment has been collapsed.

firefox has a addon that does that clicky

10 years ago
Permalink

Comment has been collapsed.

Reverse SSH tunnel is your most secure method.

10 years ago
Permalink

Comment has been collapsed.

Will look into it more at work,never heard of it before.

10 years ago
Permalink

Comment has been collapsed.

Cut off their fingers.

10 years ago
Permalink

Comment has been collapsed.

Get a Linux firewall as router. I've used IPCop a bit before. It's nice and pretty easy.
The important thing is that you filter outgoing connection to allow only standard ports like TCP 21, 80, 443.
You can just set iptables (firewall application) in your linux firewall for that.
squid proxy with something like privoxy will help filtering HTTP content too if you want.

Also squid can be setup as transparent proxy so it auto intercept port 80 traffic to proxy which mean no need to setup proxy on each computer. Note that this won't work with HTTPS. (there's a one-checkbox-and-done in IPCop web interface)

If you go more advance, you might want to go for Application firewall (the one that don't only block port but also analyse protocol upto layer 7). Haven't done that. I just know it exist.

10 years ago
Permalink

Comment has been collapsed.

I see.

So,i would need another PC with linux,which would have the internal and external network card (to pass the signal onto switch/main router).
Can do that.

Will have to look into how that IPCop behaves,ill be testing it during next week to see if i can come up with something good.

Cheers to you and all the other's for usefull info on this question.

10 years ago
Permalink

Comment has been collapsed.

You can have it as your virtual machine, assuming if you already have Hyper-V or ESX or whatever. It use very cheap resource. The two (or more) network card can be hooked up as 1 real card and use VLAN tagging.
If you don't run on VM, from what I know (which is a few years back), VLAN tagging is not possible on fresh install.

10 years ago
Permalink

Comment has been collapsed.

I used to use Vyatta ( mostly for security and load balance rather than filtering but security and censorship always go hand in hand ), it might be worthwile to test it as well as an alternative to IPcop.

10 years ago
Permalink

Comment has been collapsed.

You can also use Active Directory, if you are on a MS environment,

10 years ago
Permalink

Comment has been collapsed.

Buy PaloAlto Firewall

10 years ago
Permalink

Comment has been collapsed.

Untangle. I put it in place, worked fine. Some ways around it, but shaddup and dont tell em.

10 years ago
Permalink

Comment has been collapsed.

Download Internet Explorer

10 years ago
Permalink

Comment has been collapsed.

What are you going to block? Blocking porn and torrents is fine. Blocking half the internet (including Reddit) isn't. Because then you'll get people constantly staring at their personal phones and tablets.

10 years ago
Permalink

Comment has been collapsed.

Porn,torrents,facebook.
Will track youtube stats.

Its not about being productive,workers can have fun and buzz whenever they want if they did what they were supp to do.
Reason behind this is more of a technical nature,lots of torrents,youtube,internet radios or whatever are slowing down the network,thus preventing workers to access some data from our local server.
Cant really pin down a reason behind,so i'll eliminate 1 at the time,the big usage of a bandwitch being first in lina.

10 years ago
Permalink

Comment has been collapsed.

For a start, block everything but ports 80 and 443. That will take care of most of your problems. YouTube shouldn't be a big deal; people mostly use it for music in the background, and that doesn't take a lot of bandwidth, unless they specifically go 720p or higher.

10 years ago
Permalink

Comment has been collapsed.

well,i'll be rolling with untangle for now,when i've got this far already.
Cant tell what they were using for and how much,just know the firm's networks been unreliable lately.
Gotta start checking things.

First it was limited connection issue,with unreachable DNS adresses(which i guess was due to DHCP),now this.

10 years ago
Permalink

Comment has been collapsed.

remove the gateway or simply cut those wires, but that means no pr0n for you too!

10 years ago
Permalink

Comment has been collapsed.

Doesn't Tor work for this? I never had to try. Back when I was in school, all you had to do was https xD The very next day it stopped working as if they caught on.

10 years ago
Permalink

Comment has been collapsed.

If you block the known TOR nodes and the places where you can download TOR, and if you set up rules to alert you if there are any suspicious connections, you have done enough imho as far as a casual company needs are going ( i wouln't expect serious needs to be discussed here ).

If your employees are motivated enough to use TOR say on a usb key ( if you haven't disabled USB ), or to go around ( by sending it to themselves by mail for example ) and install it despite the fact that they are locked in a very limited environment where you shouldn't be able to install nor run tor ( tell me you are using something like SElinux instead of having every employee be a superadmin )...

then you have grounds for replacing your employee or learn yourself how to motivate them to work.

10 years ago
Permalink

Comment has been collapsed.

Quick update:
Went ahead and tried Untangle first,looked most user friendly.
Installed it onto PC,but run into the issue of not detecting network cards.
Read about it,looks like a PC i took for gateway is too old.
Will see to use another PC/buy network card/try installing drivers tomorrow.

10 years ago
Permalink

Comment has been collapsed.

Closed 10 years ago by 4evra.