Click here to get back home

Internet access

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Internet access reptil 12-08-2007
Posted by Mathieu CHATEAU on December 10, 2007, 5:50 am
Please log in for more thread options
I don't have pix anymore on the hand, but you may use some basic feature to
achieve your goal.

I think you may add basic cisco authentification on the rule that allow
http/https outside. If so, you may use local account on the pix, or use
radius (IAS on the Windows server) to let them authenticate with their
windows account.
As i don't have a pix on hand, and i was used to bigger one, it may not be
possible.



--
Cordialement,
Mathieu CHATEAU
English blog: http://lordoftheping.blogspot.com
French blog: http://www.lotp.fr


> 515E
> Ok, :))), that is problem. If I restrict IE or firefox there is
> possibillity for download on all other ports.
> This 2 people use a same computers like other 10 people in this room
> because we work in 3 shifts and this 2 people work just in 1st shift.
> Now I have restricted IP's on PIX, so I'm finding new solution, but the
> best solution is as I think it is with proxy.
>
> Thnx for advices
>
>
>
>>What is your pix model ? 501 ?
>>
>>You may tweak IE with bad proxy through GPO (and firefox through a custom
>>ADM), but that won't stop bad guys (or people with more knowledge).
>>
>>Does these 2 people have their own personal computers ? If so, you can
>>easily restrict by ip addresses.


Posted by reptil on December 10, 2007, 6:09 am
Please log in for more thread options
Thnx.

I will check possibillities. I didn't work with RADIUS server never so I must
read about that.


>I don't have pix anymore on the hand, but you may use some basic feature to
>achieve your goal.
>
>I think you may add basic cisco authentification on the rule that allow
>http/https outside. If so, you may use local account on the pix, or use
>radius (IAS on the Windows server) to let them authenticate with their
>windows account.
>As i don't have a pix on hand, and i was used to bigger one, it may not be
>possible.

Posted by Mathieu CHATEAU on December 10, 2007, 6:20 am
Please log in for more thread options
start with trying local cisco account, if it works, you may then use radius

--
Cordialement,
Mathieu CHATEAU
English blog: http://lordoftheping.blogspot.com
French blog: http://www.lotp.fr


> Thnx.
>
> I will check possibillities. I didn't work with RADIUS server never so I
> must read about that.
>
> wrote:
>
>>I don't have pix anymore on the hand, but you may use some basic feature
>>to
>>achieve your goal.
>>
>>I think you may add basic cisco authentification on the rule that allow
>>http/https outside. If so, you may use local account on the pix, or use
>>radius (IAS on the Windows server) to let them authenticate with their
>>windows account.
>>As i don't have a pix on hand, and i was used to bigger one, it may not be
>>possible.


Similar ThreadsPosted
HELP Needed: Win2k3 - How to restrict Internet access after log on expires. June 23, 2006, 10:24 am
for internet December 18, 2006, 7:21 am
internet restriction July 22, 2005, 2:33 am
Monitoring of Internet Usage by Staff March 2, 2006, 6:17 am
Internet Crimes are on the Rise and Deadlier than Ever May 7, 2006, 1:41 pm
Block a Win2k3 username from the internet June 8, 2007, 9:55 am
Block Non-Domain users from the internet December 20, 2007, 5:02 pm
Internet Zone Default security May 11, 2008, 9:00 pm
Internet Explorer Enhanced Security Configuration April 7, 2006, 10:00 am
Re: How Do I Set My Windows Server 2003 R2 Internet Zone to Medium-Hig November 26, 2007, 4:11 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap