Denying Internet site specific access via ISA
by Bill Dunn » Fri, 08 Oct 2004 06:58:47 GMT
Greetings...
I am attempting to restrict interest access by one client to a specific
internet site and not gaining much headway.
SBS2K SP1, DHCP enabled, 2 NICS and broadband. Clients running ISA firewall
client.
Here's what I have done so far and I must be missing something since the
client (Win2K) can still access the site I am attempting to restrict.
In ISA, set a Policy Element / Destination Set to the site I want to
restrict. I've done with twice - 1 with the FQDN and the other using the
sites actual IP address.
In ISA Access Policy, set a policy with the Destination set to the
"forbidden" sites FQDN. Created another with the forbidden sites actual IP
address. Action tab set to Deny and Apply Tab set to my local client user.
Another one created with apply to tab set to local user client (internal
network) computer name.
Nothing works... they can still reach the outside internet site even after
updating the ISA firewall client with the Update Now tab.
I'm sure I'm missing something but can't seem to figure out what that may
be.
Any ideas appreciated.
Bill Dunn
Re: Denying Internet site specific access via ISA
by Adam Rippon » Fri, 08 Oct 2004 07:08:18 GMT
Bill,
See link below...
http://www.**--****.com/
Regards
Adam
Re: Denying Internet site specific access via ISA
by Marina Roos [SBS-MVP] » Fri, 08 Oct 2004 07:24:34 GMT
Hi Bill,
Any help here:
Smallbizserver.Net > SBS 2000 > ISA Server 2000 > ISA for Dummies:
http://www.**--****.com/
--
Regards,
Marina
Microsoft SBS-MVP
"Bill Dunn" < XXXX@XXXXX.COM > schreef in bericht
firewall
user.
Re: Denying Internet site specific access via ISA
by Bill Dunn » Wed, 13 Oct 2004 09:52:04 GMT
Thanks for the pointers/ I've been out of town and just got around to
playing. the references were helpful but I think I must be missing
something. Here's what I have now -
Destination set with blocked site FQDN and IP elements
Client Address set with the one client computer IP address listed
Site and Content rules (2) 1 for internet access policy & the 2nd for the
blocked site destination set set up as per MS KB 300492
My problem is that IF I set the Site & Content Deny Rule to apply to "Users
& Groups", enter the apply to using the users name (e.g. domain\userID), the
client can still gain access to the deny site. HOWEVER, If I apply the rule
to the Client Set that has the client's IP address, all works fine.
Is there some way to make this deny apply to specific users so that if they
travel to a different client computer, they will still not be able to gain
access to the prohibited site?
Thanks much,
Bill Dunn
firewall
user.