• A Great friend to the HardForum with a great kid that he is trying to get a scholorship to continue his schooling. Please give hime a vote! Only 24 hours left! Thanks.
    If you have an VOTE FOR KEENAN!

Selectively blocking web sites

SemiLucid

n00b
Joined
Dec 20, 2011
Messages
25
We have a small network of half a dozen PCs. What I want to do is restrict access on two of these machines to approved web sites only (white list). Is there a cost effective way to do this for a business with no specific IT budget?

I have tried net filtering software and firewalls in the past, but they seem really finicky about what they will let through and tend to block windows update.

Things I have tried that didn't work:

A consumer Netgear router blocks globally and not by selected PC. It also fails to block HTTPS sites like Facebook.

Norton Online Family (an online web filter) lets undesirable websites through even though I chose to block all categories and rely on a white list.

I can't use OpenDNS as I have seen their forum moderators mention there are latency issues with users in New Zealand.
 
If OpenDNS is not an option, the most cost effective way to take care of this is to have an Acceptable Computer Use Policy signed by each employee. Make it so they cannot delete their Internet History or invoke Private Browsing Modes and enforce the policy.
 
You can run Peerblock as a service at boot with no icon and block all access except a whitelist of IPs.
http://www.peerblock.com/

If they dont have admin access, they cant modify it.
Save the whitelist somewhere with restricted access on the machine.
 
Just download K9 web blocker on each PC. 6 PC's is not bad to manage individually and its free
 
Barracuda Web Security Service: https://www.barracuda.com/products/websecurityflex

You can get a subscription as small as 5 users for about 10 bucks a user per year. You have a choice of directly proxying to the service or installing a silent agent that blocks sites. The rules are controlled from the cloud through a web portal.
 
Whitelisting is selectively ALLOWING, not selectively blocking.

This is why people bitch about products not doing what they need, it's because they don't know what they need, or don't know the meaning of the words they say. ANYwho..


OpenDNS works fine for this, but you seem to be on the other side of the planet, so resolution time is going to suck.. Create a local forwarding (caching) resolver that forwards to OpenDNS. Done. Local machines will ask the caching local resolver, getting a nice and quick response for cached entries.
 
Back
Top