ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    web filtering using Host file

    Scheduled Pinned Locked Moved IT Discussion
    37 Posts 3 Posters 4.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • IT-ADMINI
      IT-ADMIN
      last edited by

      firewall rules can block traffic based on IPs, not URLs

      scottalanmillerS 1 Reply Last reply Reply Quote 0
      • IT-ADMINI
        IT-ADMIN
        last edited by

        aahh i see what you mean Mr Scott, i should block all traffic except for outbound traffic going to my proxy server

        scottalanmillerS 1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller @IT-ADMIN
          last edited by

          @IT-ADMIN said:

          firewall rules can block traffic based on IPs, not URLs

          And by ports, most importantly.

          1 Reply Last reply Reply Quote 1
          • scottalanmillerS
            scottalanmiller @IT-ADMIN
            last edited by

            @IT-ADMIN said:

            aahh i see what you mean Mr Scott, i should block all traffic except for outbound traffic going to my proxy server

            Exactly. That takes care of the general networking workaround. Now the proxy is in control of traffic and can determine where people can go.

            1 Reply Last reply Reply Quote 1
            • IT-ADMINI
              IT-ADMIN
              last edited by

              i just test it right now, but it has affected other ports like outlook, now i cannot sent and receive mails,

              scottalanmillerS 1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @IT-ADMIN
                last edited by

                @IT-ADMIN said:

                i just test it right now, but it has affected other ports like outlook, now i cannot sent and receive mails,

                Only block 80/443 for now. The proxy doesn't handle other protocols.

                1 Reply Last reply Reply Quote 0
                • IT-ADMINI
                  IT-ADMIN
                  last edited by

                  yes, i will open all ports except 80 and 443 for all destination, and for those 2 ports i should forward them only to the proxy IP

                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                  • IT-ADMINI
                    IT-ADMIN
                    last edited by

                    yes, now i understand your wise sentence, proxy by itself cannot do the job except with the collaboration of the firewall rules

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @IT-ADMIN
                      last edited by

                      @IT-ADMIN said:

                      yes, i will open all ports except 80 and 443 for all destination, and for those 2 ports i should forward them only to the proxy IP

                      Exactly.

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @IT-ADMIN
                        last edited by

                        @IT-ADMIN said:

                        yes, now i understand your wise sentence, proxy by itself cannot do the job except with the collaboration of the firewall rules

                        🙂 Yes, one for the networking portion and one for the web portion.

                        1 Reply Last reply Reply Quote 0
                        • IT-ADMINI
                          IT-ADMIN
                          last edited by

                          yes you are right, thank you very much for your help and willingness to share your knowledge

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @IT-ADMIN
                            last edited by

                            @IT-ADMIN said:

                            yes you are right, thank you very much for your help and willingness to share your knowledge

                            Glad to help 🙂

                            1 Reply Last reply Reply Quote 0
                            • IT-ADMINI
                              IT-ADMIN
                              last edited by

                              by doing this portable browser cannot access the web unless they enter proxy setting (of the proxy), so they will be obliged to pass through the proxy, otherwise they cannot access the web

                              scottalanmillerS 1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @IT-ADMIN
                                last edited by

                                @IT-ADMIN said:

                                by doing this portable browser cannot access the web unless they enter proxy setting (of the proxy), so they will be obliged to pass through the proxy, otherwise they cannot access the web

                                Correct

                                1 Reply Last reply Reply Quote 0
                                • IT-ADMINI
                                  IT-ADMIN
                                  last edited by

                                  and if they don't know my proxy setting they will contact me so that i will know who try to bypass the company policies and then i will make for them a good report with the manager hhhhhh

                                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @IT-ADMIN
                                    last edited by

                                    @IT-ADMIN said:

                                    and if they don't know my proxy setting they will contact me so that i will know who try to bypass the company policies and then i will make for them a good report with the manager hhhhhh

                                    True. Although they will probably just fall back to the company browser at that point.

                                    1 Reply Last reply Reply Quote 0
                                    • IT-ADMINI
                                      IT-ADMIN
                                      last edited by

                                      hhhhhh, but still there is a way to access facebook even with all of these precaution and setting, online proxy browser, this way you cannot do anything

                                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                                      • IT-ADMINI
                                        IT-ADMIN
                                        last edited by

                                        and these online proxies are many, you cannot block all of theme

                                        1 Reply Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller @IT-ADMIN
                                          last edited by

                                          @IT-ADMIN said:

                                          hhhhhh, but still there is a way to access facebook even with all of these precaution and setting, online proxy browser, this way you cannot do anything

                                          Correct, short of whitelisting there is absolutely nothing that you can do. Which is why, at the end of the day, it's generally best to not block and let HR retain people who work well and fire those who do not. Really, at the end of the day, people will just do it from their phones if you block it. Making them even less productive.

                                          1 Reply Last reply Reply Quote 0
                                          • IT-ADMINI
                                            IT-ADMIN
                                            last edited by

                                            yes but you don't have the choice, the administration think that blocking those website they will improve productivity, and i have to make what they ask me to do, the problem here my situation will be very embarassing if the manager know that someone still have the ability to access facebook or youtube, and the worst the manager don't understand that you cannot block all online proxies, he will think that you are not sharp enough to do the job

                                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 2 / 2
                                            • First post
                                              Last post