Koozali.org: home of the SME Server

Restrict Access from Internal Network

Offline ScottieDog

  • *
  • 13
  • +0/-0
Restrict Access from Internal Network
« on: June 02, 2009, 03:21:13 PM »
We use SME 7.4 as backup gateway in a Microsoft School environment. The internal IP address is of course on the same subnet as the other servers.

Some students have discovered they can manually point their browser to the SME box and get unfiltered access to the Internet.

Can somebody advise me how I can restrict only a few specific computers to be allowed access to the SME server from the internal network ?

Thanks in advance.

Offline versa

  • ****
  • 109
  • +0/-0
Re: Restrict Access from Internal Network
« Reply #1 on: June 02, 2009, 05:27:56 PM »
You could try Dansguardian and filter the connections
http://wiki.contribs.org/Dansguardian

or a search gave me this
http://forums.contribs.org/index.php/topic,33613.0.html
......

Offline mmccarn

  • *
  • 2,656
  • +10/-0
Re: Restrict Access from Internal Network
« Reply #2 on: June 03, 2009, 02:17:56 PM »
Here are some notes on blocking outbound traffic: http://wiki.contribs.org/Firewall#Block_outgoing_ports

This method does *not* prevent access to the web or smtp proxy servers, so you would still need to address those issues.

The SMTP proxy can simply be disabled.

For the web proxy, you could install DansGuardian or you might get what you want by configuring your SME to use your regular proxy as an "upstream proxy" -- then the clever students could redirect their browsers, but they'd still be using your main proxy...

I've never used it, but you may be interested in http://wiki.contribs.org/Vnstat so you can monitor what goes through your SME.