MHCG
New Member
- Reaction score
- 0
- Location
- Southeast Arizona
We have a large network with win2k3 terminal servers that users login on and use to connect to the internet through. We need to limit some user's internet access to a specific list of websites and other users should have unlimited internet access.
The terminal servers are all on a domain and of course we use active directory. In order to do this, it seemed that the best way to differentiate is through group policy being applied to specific OUs.
I can't use services like openDNS because it doesn't exist on the internet we use (it's a secure government internet) and we can only use a limited number of pre approved applications and solutions like this aren't on that list.
My thought was that I could set up a proxy server with white lists and have specific user's internet access go through the proxy server. Or, somehow do it through Internet Explorer's security settings. I thought about using a DNS server I create for the limited users, but I don't know that I can apply that to users since it's usually a computer based policy and because limited and unlimited user's will use these terminal servers, I can't restrict it by computer.
Any other ideas?
The terminal servers are all on a domain and of course we use active directory. In order to do this, it seemed that the best way to differentiate is through group policy being applied to specific OUs.
I can't use services like openDNS because it doesn't exist on the internet we use (it's a secure government internet) and we can only use a limited number of pre approved applications and solutions like this aren't on that list.
My thought was that I could set up a proxy server with white lists and have specific user's internet access go through the proxy server. Or, somehow do it through Internet Explorer's security settings. I thought about using a DNS server I create for the limited users, but I don't know that I can apply that to users since it's usually a computer based policy and because limited and unlimited user's will use these terminal servers, I can't restrict it by computer.
Any other ideas?
Last edited: