View previous topic :: View next topic |
Author |
Message |
Crimson Rider Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
![](images/avatars/gallery/Final Fantasy/Final_Fantasy_8_-_Zell.gif)
Joined: 23 Jun 2003 Posts: 462 Location: Delft, the Netherlands
|
Posted: Fri Jul 15, 2005 8:55 am Post subject: Detecting and Blocking Sites |
|
|
Now to the other end of the spectrum, a few posts ago I asked for a solution on stealthed internet. Using OpenVPN and a few pointers I made that happen. Thank you.
Now, in yet another capacity, that of sysadmin, I need to be able to detect what sites my users are surfing to, and block access to these sites if management deems them inappropiate for work.
All the users use internet via a central Gentoo firewall, I am mostly interested in blocking MSN and maintaining a list of sites visited. I am not interested in who visited what, only in what sites where visited. And of course, I need to somehow maintain a list of blocked sites, and block those sites.
Any tips?
Thanx. _________________ Code, justify, code - Pitr Dubovich |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
nx12 Apprentice
![Apprentice Apprentice](/images/ranks/rank_rect_2.gif)
![](images/avatars/20592613344068a1d1c3943.jpg)
Joined: 14 Jan 2004 Posts: 193
|
Posted: Fri Jul 15, 2005 3:17 pm Post subject: |
|
|
Check the squid web-cache. There's plenty of docs on there page.
Also you can configure iptables on your firewall box to dump all the http requests your users do as well as put some rules to block whatever you feel like to block. Google is your best friend here _________________ signature sucks |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
think4urs11 Bodhisattva
![Bodhisattva Bodhisattva](/images/ranks/rank-bodhisattva.gif)
![](images/avatars/8534934054bad29b51e5fa.jpg)
Joined: 25 Jun 2003 Posts: 6659 Location: above the cloud
|
Posted: Fri Jul 15, 2005 8:21 pm Post subject: |
|
|
1) only allow internet access through a proxy - NO outgoing nat
2a) squid, blocking via acls in the config
2b) squid combined with either squidguard or dansguardian plus a good URL database (ads, porn, violence, whatever)
3) calamaris for the reporting
doesn't stop all your users completely but most of them (tunneling through proxy to an external 'free' proxy etc.) _________________ Nothing is secure / Security is always a trade-off with usability / Do not assume anything / Trust no-one, nothing / Paranoia is your friend / Think for yourself |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Antimatter Guru
![Guru Guru](/images/ranks/rank_rect_3.gif)
Joined: 11 Aug 2003 Posts: 463
|
Posted: Fri Jul 15, 2005 8:44 pm Post subject: |
|
|
Think4UrS11 wrote: |
doesn't stop all your users completely but most of them (tunneling through proxy to an external 'free' proxy etc.) |
is it possiable to block tunneling though the proxy to an exterial proxy? |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
think4urs11 Bodhisattva
![Bodhisattva Bodhisattva](/images/ranks/rank-bodhisattva.gif)
![](images/avatars/8534934054bad29b51e5fa.jpg)
Joined: 25 Jun 2003 Posts: 6659 Location: above the cloud
|
Posted: Fri Jul 15, 2005 8:47 pm Post subject: |
|
|
depends on the knowledge of your users
one way would be to use a white list instead of a black list of sites but that gives a huge adminstrative burden... _________________ Nothing is secure / Security is always a trade-off with usability / Do not assume anything / Trust no-one, nothing / Paranoia is your friend / Think for yourself |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
jdmulloy Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/114454834747cf6999b0ef0.jpg)
Joined: 24 Dec 2004 Posts: 139 Location: Massachusetts, USA
|
Posted: Fri Oct 14, 2005 1:21 am Post subject: Dansguardian is a content filter |
|
|
While dansguardian has a black list it also checks the pages so that if the filter deems it inappropriate even an external proxy won't work.
Last edited by jdmulloy on Sun Apr 09, 2006 6:41 pm; edited 1 time in total |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
HeXiLeD Veteran
![Veteran Veteran](/images/ranks/rank_rect_5_vet.gif)
![](images/avatars/151607204746643085a95a8.jpg)
Joined: 20 Aug 2005 Posts: 1159 Location: Online
|
Posted: Thu Mar 30, 2006 1:39 am Post subject: |
|
|
A very good way of blocking access to certain sites/ip's/domains is using a hosts file.
Take a look here _________________ Do you hear the sound of inevitability?
With age, comes great grumpiness and that, was 20 years ago...
CertFP: becbbd161d5a5c31de3c45171b77bf710911db29 / d985d21f89fe2977b593c4d381a1a86802e62990d9328d893db76d59f9935244 |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|