• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Internet Filtering for Small Business

Nybbles

[H]ard|Gawd
Joined
Jun 17, 2002
Messages
1,234
I've been out of the small/medium business support for a while so please bear with the question. Essentially, I'm looking for suggestions for internet filtering for a small office with about 10 PC's, 7 users, and 1 server. The server is Windows 2003 Standard x86 w/ Service Pack 2 running an Active Directory domain.

I'm only looking for basic functionality... essentially to log sites visited by user/PC and to create white-lists and possibly black-lists. It must allow the configuration of whitelists/blacklists on a "per PC" basis -- i.e. we want to restrict the office workers without restricting the owner. We have also already considered the legal implications of this effort.

For this office, I cannot easily recommend a spare PC running Squid or other open-source software. I was thinking of something along the lines of proxy software running on the server, and could use an AD GPO to configure IE on all workstations. I am also not opposed to just replacing their current router (Netgear ProSafe) with one that can do filtering, but I'm skeptical if this functionality can be flexible enough without spending a fortune.

I know there are people who visit who do consulting for the SMB market. What solutions have you put in place for this?

EDIT: There's no requirement that the solution be free. It should just be of reasonable cost for a small office.
 
Last edited:
pfsense is another good one it is free but very powerful beyond the other, untangle is also free, or paid and does a good job but does need a beefier system pending what you want to run on it.
 
what does your business do? Why are you filtering the internet in the first place? If you don't trust your employees why are you employing them in the first place?
 
Never trust employees. Basic tenet of security.

never trust your users . . . period . . . . "What the? My anti-virus isn't up to date and I should run this free scan?? Okay!"



I would look at Untangle or Astaro. If you want an appliance with suppport that you don't have to build the ASG120 from Astaro is a good system. If you don't want to spend that kind of money and you don't mind tossing something together to run it I highly recommend Untangle. Other options would be Barracuda WebFilter 210 and the St. Bernard iPrism devices although I'm not a fan of the iPrism. If you're just looking for a proxy server to throw on there server you could maybe to MS ISA???
 
Another Untangle fan here. For what you'll need you could grab one of your spare p4's off from the shelf and throw an extra nic in it. There is your untangle box
 
Could just toss in one of SonicWALLs Total Secure line. That would do all that you ask, and not be another box with moving parts to support.
 
I've been using untangle.

Endian is another. I haven't used it.

Wish PFsense had more fo the UTM stuff to it, I really liked PFsense.
 
There almost should be a sticky with all the distros out there and a list f features, strengths, and weaknesses. Questions like this do come up often.
 
There almost should be a sticky with all the distros out there and a list f features, strengths, and weaknesses. Questions like this do come up often.

I know, and I didn't want to be "that guy" to post it again. I was hoping to get suggestions for a Windows-based solutions to avoid having more hardware to maintain. Since I didn't get that, perhaps there just aren't any that are noteworthy?

what does your business do? Why are you filtering the internet in the first place? If you don't trust your employees why are you employing them in the first place?

I've actually been asked by a friend to get his business network in shape. It's a small office.... the exact nature of the business is not a factor in his desire to filter.

Essentially, the employee's need internet access for their job but they only need access to a few certain sites. There are times when the owner and his wife are out of the office and they want to ensure the employee's are working rather than surfing. I'm also hoping to limit the number of spyware/adware laden PC's I have to clean by limiting where they can go on the internet.



Overall, I think you all have presented some good filtering options, though I was hoping to avoid having to run extra hardware just for this purpose. They already have more PC's than employee's and I've been encouraging them to maintain what they have better, so I'm not very enthusiastic about recommending more machines even if they are older on spare hardware.

Anyone had any experience running these products in a VM? I'm pretty comfortable with virtualization (VCP + work with ESX at my day job) and don't see any reason there'd be issues. The new server that was purchased could very easily handle the additional load. If it were to go down it wouldn't matter that internet access would be lost as well because they'd already be dead in the water. This option might be the best trade-off between getting a flexible and robust solution in plane and not having to maintain more hardware.
 
I know, and I didn't want to be "that guy" to post it again. I was hoping to get suggestions for a Windows-based solutions to avoid having more hardware to maintain. Since I didn't get that, perhaps there just aren't any that are noteworthy?



I've actually been asked by a friend to get his business network in shape. It's a small office.... the exact nature of the business is not a factor in his desire to filter.

Essentially, the employee's need internet access for their job but they only need access to a few certain sites. There are times when the owner and his wife are out of the office and they want to ensure the employee's are working rather than surfing. I'm also hoping to limit the number of spyware/adware laden PC's I have to clean by limiting where they can go on the internet.

Overall, I think you all have presented some good filtering options, though I was hoping to avoid having to run extra hardware just for this purpose. They already have more PC's than employee's and I've been encouraging them to maintain what they have better, so I'm not very enthusiastic about recommending more machines even if they are older on spare hardware.

Anyone had any experience running these products in a VM? I'm pretty comfortable with virtualization (VCP + work with ESX at my day job) and don't see any reason there'd be issues. The new server that was purchased could very easily handle the additional load. If it were to go down it wouldn't matter that internet access would be lost as well because they'd already be dead in the water. This option might be the best trade-off between getting a flexible and robust solution in plane and not having to maintain more hardware.

Really look into the untangle. I think after you play with it, you'd get to like it. It has active spyware/virus scanning, and can block pages by category or url, and will give you reports of what each ip is looking at. There is also an AD connector so if you use AD you can get clearer reporting.

Also look into the opendns.org. You can block pages based on url, or, category. It will also tell you the top page hits, and top hits on blocked categories.

If you do decide to do untangle and opendns, you can also use a company logo, so no one would really know it was untangle or opendns. Opendns is free, untangle wants money for a logo, unless, you install an older version (5.3) and do your logo/comapny info/contacts, then upgrade.
 
Anyone had any experience running these products in a VM? I'm pretty comfortable with virtualization (VCP + work with ESX at my day job) and don't see any reason there'd be issues. The new server that was purchased could very easily handle the additional load. If it were to go down it wouldn't matter that internet access would be lost as well because they'd already be dead in the water. This option might be the best trade-off between getting a flexible and robust solution in plane and not having to maintain more hardware.

I've run Untangle successfully in a VM. You'll want to make sure you have at least one NIC dedicated for the outside interface, the inside can use a shared NIC.

Astaro also runs well in a VM. You can even download a pre-built virtual appliance.
 
If you're looking for a client software solution, we use Webroot Web Filtering at a few clients with decent results. It's a couple bucks per month per user, they give you a proxy server plus web based configuration tools, you just point your browsers at the proxy server. The web based config lets you create users and groups, and then set specific configuration for either. Does all the usual reporting and logging as well. Works well, plus no software to maintain on the server, which is why we like it.

Also, since it's an externally hosted proxy server, you can enforce proxy settings for mobile users. This is the one feature that our clients love. No more users taking laptops home, browsing porn/getting viruses, then bringing it back to the office and plugging it into the network.
 
If you're looking for a client software solution, we use Webroot Web Filtering at a few clients with decent results. It's a couple bucks per month per user, they give you a proxy server plus web based configuration tools, you just point your browsers at the proxy server. The web based config lets you create users and groups, and then set specific configuration for either. Does all the usual reporting and logging as well. Works well, plus no software to maintain on the server, which is why we like it.

Also, since it's an externally hosted proxy server, you can enforce proxy settings for mobile users. This is the one feature that our clients love. No more users taking laptops home, browsing porn/getting viruses, then bringing it back to the office and plugging it into the network.

Never used webroot, but opendns seems like it would be easier. Just pop in the opendns servers on your router, etc and all pc's on the network are covered.

http://www.opendns.com/

Also has web based tweaking.
 
I am curious as to the router that is being used. I know in some of the open-source firmwares like DD-WRT, you can set it up to have VLAN;s. The idea being the bosses computer is on a VLAN with a normal DNS, the other users are on a VLAN that goes through the restricted OpenDNS or some other sort of filter. Just an idea.
 
I would recommand using opendns. Like what the other people said. Make the server of your business
use the open dns ips. OpenDNS have account setup that you can use to set filters that blocks sites like myspace.
 
I would recommand using opendns. Like what the other people said. Make the server of your business
use the open dns ips. OpenDNS have account setup that you can use to set filters that blocks sites like myspace.

only problem with that is crafty users change their primary dns server to something like 4.2.2.2 and there goes your filtering.
 
This is true Captain Colonoscopy (LOL). I know programs like DD-WRT also allow you to create white and blacklists (under the Access Restrictions) and base it on computer IP or mac addresses.
 
only problem with that is crafty users change their primary dns server to something like 4.2.2.2 and there goes your filtering.

Then they spend a 1/2 hour watching "applying computer settings" when they boot up in the morning, 'n can't find stuff on the servers...cuz internal DNS 'n AD is tanked.

'course really crafty users can flip around 'n change DNS back 'n forth on the fly....
 
It's a constant battle, as users try their hardest to screw around and infect PC's. Okay maybe they don't try, but they are still too dumb to know better. Especially the clever ones that find ways around your security measures. Those ones are the most dangerous!
 
This is true Captain Colonoscopy (LOL). I know programs like DD-WRT also allow you to create white and blacklists (under the Access Restrictions) and base it on computer IP or mac addresses.

True, true. If you have a decent firewall you could block access to DNS servers other than OpenDNS for sure. :D
 
It's a constant battle, as users try their hardest to screw around and infect PC's. Okay maybe they don't try, but they are still too dumb to know better. Especially the clever ones that find ways around your security measures. Those ones are the most dangerous!

then you should be giving them acceptable use policy letters to sign and when they break those rules they get written up and go from there, period.

Your works arent your friends, if they are damaging company property they deserve to get punished, you at work to work, not check your email, go on IM's and other crap, do that on your own time.
 
They do sign proper usage forms, and the department managers deal with them. As it comes out of their budget department, employees still break stuff. Waiting on captive portal for Untangle ;) So I can blast the policy right in their face!
 
^ haha, that will be awsome! get ready for alot of people "complaining" about what they cant do..lol


i sent out a notice in our office i am implenting a new firewall system (pfsense with squid and proxy) and said that things will be locked down tight and if you need access this is the procedure, tired of people sitting on youtube all day and crap sucking up our bandwidth and then people complain external reports are slow and is the same people sucking up the bandwidth.
 
SonicWALLs are great. Definitely love installing and using them.

For a small business I'd look hard at a sonicwall as well. Thing is for the price they could get a nice untangle box or something similar up and running. We have a few clients running tz-170's or 180s(can't remember) that we got when we took them over. I was pretty impressed with them. We had been installing cisco 870's at clients that wanted something better then the basic low end.

As of late we have installed a few tz-190's at various sites. Have another that will be ordered prob by the end of the week. We generally get the unlimited user license ones and on sites that want it subscribe to the premium content filter.

True, true. If you have a decent firewall you could block access to DNS servers other than OpenDNS for sure. :D

Yea but with a decent firewall you can probability run content filtering from it.

^ haha, that will be awsome! get ready for alot of people "complaining" about what they cant do..lol


i sent out a notice in our office i am implenting a new firewall system (pfsense with squid and proxy) and said that things will be locked down tight and if you need access this is the procedure, tired of people sitting on youtube all day and crap sucking up our bandwidth and then people complain external reports are slow and is the same people sucking up the bandwidth.

Yea really. I pissed someone off when I told them they could view youtube on their phone instead.

I remember setting up a basic block at a small client a while ago to block myspace, facebook, and aim. Configured the new router and swaped it out for the old one. Made sure the internet was up and running and myspace was blocked at got up to tell my contact. As I do one of the old guys that worked there walked by laughing telling me that I was getting ready to get my ass kicked by a bunch of angry white women. They realized what happened and were bitching in less then 2 minutes from the new router going in.
 
^ haha, that will be awsome! get ready for alot of people "complaining" about what they cant do..lol


i sent out a notice in our office i am implenting a new firewall system (pfsense with squid and proxy) and said that things will be locked down tight and if you need access this is the procedure, tired of people sitting on youtube all day and crap sucking up our bandwidth and then people complain external reports are slow and is the same people sucking up the bandwidth.

I made a bold move and just installed Untangle over the weekends. Lots of calls, and lots of its for the good of the company, now get back to work responses. I pretty much have full reign over IT dept decisions and can do whatever is necessary. Even the owners understand, they say that they pay me so they don't have to worry about these things. So I do everything that I can with what I am allotted to spend.

For a small business I'd look hard at a sonicwall as well. Thing is for the price they could get a nice untangle box or something similar up and running. We have a few clients running tz-170's or 180s(can't remember) that we got when we took them over. I was pretty impressed with them. We had been installing cisco 870's at clients that wanted something better then the basic low end.

As of late we have installed a few tz-190's at various sites. Have another that will be ordered prob by the end of the week. We generally get the unlimited user license ones and on sites that want it subscribe to the premium content filter.
/QUOTE]

As for a sonicwall, I have a TZ-170 if anybody is in need cheap, let me know and I'll make it official in the FS/FT forum. No clogging up this thread... On that note I still recommend UT, my first boxes were basic 1U servers with dual 2.0 opterons and 2gb ram, 80gb hdd, for about $600 shipped from the egg.
 
Just a followup .....

Put Untangle into a VM with a few client machines in my home lab last Thursday. First impressions: Wow, this is a polished product! I'd heard of it before but disregarded it figuring it was like all the other *nix-based firewall/router distributions.

Performed the server migration for the client on Saturday; this included the installation of Untangle 6.20 (free version) in a virtual machine on VMware Server 2.0.

The only "oddity" we experienced was with Untangle's web filtering. It seemed to only be intermittently filtering traffic that should have been denied by the block list. And the times it didn't filter, it didn't log the traffic at all but passed it anyway. Per my Google searches, the "fix" for this in previous versions was to wait 6 hours for the automatic filtering database update task to run, or force it to run manually. I'm unsure if this version is affected by the same bug, but earlier this morning, client PC's seemed to be getting filtered more reliably. We'll watch its behavior over the next few days.

Overall, it's a pretty nice product and was worth the extra work. Thanks for recommending it.
 
Back
Top