• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Blocking Facebook

/usr/home

Supreme [H]ardness
Joined
Mar 18, 2008
Messages
6,160
So we have a client that we currently have Facebook blocked with via DNS on the domain controller. Facebook.com just redirects to the IP of the server. Each workstation points to the IP of the DC for it's DNS so that works out well. (If they really wanted to, they could change the DNS servers, but that would make their logins slow and most if not all the users would even know how to do that.) We have had this setup for about a year, and the owners of the business are happy with it and how's it working. They now have a Facebook page that they want to update at work, but obviously they can't get on Facebook. (We told them to do it at home, but "apparently" it doesn't work there. Whatever.) It's only one computer that needs access or one user I guess, but preferably computer. Is there a way, maybe through GPO or the DNS server itself that would allow only the specific computer and none others through? The server is running Server 2003 and the clients are XP pro with maybe one or two 7 machines. Any ideas?
 
So we have a client that we currently have Facebook blocked with via DNS on the domain controller. Facebook.com just redirects to the IP of the server. Each workstation points to the IP of the DC for it's DNS so that works out well. (If they really wanted to, they could change the DNS servers, but that would make their logins slow and most if not all the users would even know how to do that.) We have had this setup for about a year, and the owners of the business are happy with it and how's it working. They now have a Facebook page that they want to update at work, but obviously they can't get on Facebook. (We told them to do it at home, but "apparently" it doesn't work there. Whatever.) It's only one computer that needs access or one user I guess, but preferably computer. Is there a way, maybe through GPO or the DNS server itself that would allow only the specific computer and none others through? The server is running Server 2003 and the clients are XP pro with maybe one or two 7 machines. Any ideas?

can't you just block it on your firewall ? Create a rule to a internal page that says HEY no facebooking :)
 
i would put on the DC to disable changing NIC properties, then no worries about people changing things.

get untangle :D use the webfilter rule and esoft and the policy rack = block facebook from everyone you need to, and allow who you want to allow, even allow specific FB URLS to people too.

if your blocking it in the DNS server i dont see how you could let through just one computer unless you set that computer with external DNS and not to go through your DC and not join it on the domain?
 
Yeah, I didn't at all set any of this up, I just semi-inherited it. We have 4 technicians plus our former boss (sold the company 2 months ago) so things can be pretty half-assed \ done the improper way and it's really hard to reimplement things the right way, if not almost impossible since the business is used to their network being like this and for the most part it's working fine. So there's basically 4 people who do work on their stuff who all do things differently and nonstandardized and it's a mess... I'm not bragging or anything, but I seem to be the only one who knows how and WANTS to do things properly. We do many other businesses and many of them are half-assed and poorly setup like this, all of which I get to patch and try and get them by with mickey-mouse ways. Thanks for the help guys.
 
i hate that thought, managers dont do their job and just let people do what hey want.

the 4 techs need one in charge to report to and proper structure, at our company it is me and one guy below me and things get done how i say they get done.
 
I'm one of the 4 and while we have a person telling us what to do, she herself has no idea how to do anything. She just schedules stuff. We do retail stuff like upgrades and troubleshooting and virus removals, data transfers, that kind of stuff. We also do contract work for banks and other businesses that have contracts with IT outsourcing companies and then we have local businesses (city of 17,000) and a huge area outside the city to cover. Nothing HUGE, but many little networks and businesses. The problem is that we might randomly get assigned to a place we have never been before so the tech going doesn't know the setup (most are documents poorly, if at all) and the tech who did set it up is no longer working with us or on another call or inhouse. I find it VERY frustrating. I would love to just have one large network to admin and do IT for where things are done properly. Not necessarily MY way, just the correct way and things are standardized and everything is done the same. But jobs like that around here (SK, Canada) are very rare and few in between. Besides that part I do love my job, just not the frustration of other people's half-asseness.
 
I would love to just have one large network to admin and do IT for where things are done properly.
This doesn't exist in my experience. Every network gets "screwed up" by layer 8 and 9 of the OSI model, politics and money.
 
hosts file is one way or if they are on a domain and using a DC... just put it in the internet explorer rules... we do that at a client... they are prompted to enter a password for that "security zone" because we have facebook.com listed
 
can't you just block it on your firewall ? Create a rule to a internal page that says HEY no facebooking :)
^am I missing something or is that way easier than anything else posted. I just added facebook.com to forbidden domains.
 
They just bought fb.com, might want to hit that too, it looks like it just redirects for now but that could always change in the future.
 
I'm not even 100% sure, but I think they are using some POS Nortel router or something and they have other locations VPNed into this one so that could buggar things up a bit. I'll take a look into that security zone thing as well. Thanks for the tips guys.
 
Back
Top