Click here to get back home

HELP Needed: Win2k3 - How to restrict Internet access after log on expires.

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
HELP Needed: Win2k3 - How to restrict Internet access after log on expires. admin 06-23-2006
Posted by admin on June 23, 2006, 10:24 am
Please log in for more thread options
Hi all,

I hope you maybe able to help this newbie to Win2k3 server gain some
control over users and internet use.


My setup, 1 x win2k3( 2 NIC), with AD and DC running, 3 x win xp pro
workstations, 1 x Win2k pro workstation, 2 x Win XP pro laptops. 8 user

accounts.


What I am trying to acheive from the win2k3 box is to force users to
logoff when logon time expires, ( example: outside office hours) as at
present only the network resources become unavailable when the logon
time expires. At present if the user logs on during office hours, the
user has all the uses of the LAN network resources and access to the
Internet during office hours. Once the logon time expires the LAN
resources are disabled ( no file sharing, no printers), but the
internet is still accessible from the WAN NIC. At present my users
frequently forget to logout. Thus leaving the internet connection open.

In the Domain security policy & Domin controller security policy I have
enabled "force logoff, when logon time expires" and "disconnect when
logon expires" in the security options tab. Is there anything further I
can do to force the client pc's off within Win2k3, as this setup so far
does not secure / limit the internet to logon hours.

Is this possible within the standard Win2k3 server setup, or is a third

party application required?

I see that Windows vista parental control provides this functionality
of internet restriction,
however this would need to be installed locally on all of the WinXP
machines and not controlled by the server.


If I have posted this to the wrong group, please accept my apologies,
and if possible advise where to post my query.



Thanks for your help in advance and any suggestions would be
appreciated


Posted by Roger Abell [MVP] on June 23, 2006, 10:44 am
Please log in for more thread options
The policies that you mention are, by what you report, functioning as
defined, as these have impact only on access Windows-based network
resources (ex. shares). Gating access to the outer internet is usually
done by use of a machine at that point, such as an ISA server.
It is not clear what you are after, to not allow internet access during
some lights out period, or to not allow any machine to be logged into
and/or otherwise used whatsoever during that lights out period.
In either event, that capability is not build into Windows and would
either need to be purchased or crafted by yourself (i.e. if no machine
use whatsoever is desired then a server-based scheduled task could
be used to effect that, although it may have some shortcomings).

> Hi all,
>
> I hope you maybe able to help this newbie to Win2k3 server gain some
> control over users and internet use.
>
>
> My setup, 1 x win2k3( 2 NIC), with AD and DC running, 3 x win xp pro
> workstations, 1 x Win2k pro workstation, 2 x Win XP pro laptops. 8 user
>
> accounts.
>
>
> What I am trying to acheive from the win2k3 box is to force users to
> logoff when logon time expires, ( example: outside office hours) as at
> present only the network resources become unavailable when the logon
> time expires. At present if the user logs on during office hours, the
> user has all the uses of the LAN network resources and access to the
> Internet during office hours. Once the logon time expires the LAN
> resources are disabled ( no file sharing, no printers), but the
> internet is still accessible from the WAN NIC. At present my users
> frequently forget to logout. Thus leaving the internet connection open.
>
> In the Domain security policy & Domin controller security policy I have
> enabled "force logoff, when logon time expires" and "disconnect when
> logon expires" in the security options tab. Is there anything further I
> can do to force the client pc's off within Win2k3, as this setup so far
> does not secure / limit the internet to logon hours.
>
> Is this possible within the standard Win2k3 server setup, or is a third
>
> party application required?
>
> I see that Windows vista parental control provides this functionality
> of internet restriction,
> however this would need to be installed locally on all of the WinXP
> machines and not controlled by the server.
>
>
> If I have posted this to the wrong group, please accept my apologies,
> and if possible advise where to post my query.
>
>
>
> Thanks for your help in advance and any suggestions would be
> appreciated
>



Posted by Paul on June 23, 2006, 10:56 am
Please log in for more thread options
Hi Roger,

I have a copy of ISA Server and a few spare pc's, do you know how I
would gate my system to acheive lock out, outside the office hours to
the internet for specific user accounts located in Active Directory.

I am unable to shut off the Internet outside of office hours, as the MD
wants access outside these times, for selected users.

Thanks for your help in advance.


Posted by Roger Abell [MVP] on June 24, 2006, 1:55 am
Please log in for more thread options
It would probably be more effective for you to review the ISA docs
for install and capabilities. Sorry, but without you having it running
we would be in hyplthetical style discussion.

--
Roger Abell
Microsoft MVP (Windows Server : Security)


> Hi Roger,
>
> I have a copy of ISA Server and a few spare pc's, do you know how I
> would gate my system to acheive lock out, outside the office hours to
> the internet for specific user accounts located in Active Directory.
>
> I am unable to shut off the Internet outside of office hours, as the MD
> wants access outside these times, for selected users.
>
> Thanks for your help in advance.
>



Similar ThreadsPosted
Block a Win2k3 username from the internet June 8, 2007, 9:55 am
Minimum File System Access Needed for a Service? December 6, 2005, 3:14 am
Restrict access to ATL COM service June 3, 2005, 2:08 pm
Internet access December 8, 2007, 11:53 am
Restrict access to COM application settings September 6, 2006, 5:00 pm
Restrict copy access on files on server June 8, 2006, 5:36 pm
RDP : restrict administrator to access system without my permission through rdp June 15, 2006, 6:49 am
How to restrict file access to Domain Computers Only August 27, 2006, 9:55 am
Restrict user access to CD,floppy and removable media December 15, 2005, 2:41 am
Uergent help needed August 25, 2005, 2:45 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap