On 26/01/02 23:54 +0530, Philip S Tellis wrote:
/me is catching up on a backlog :(

> Sometime Today, rohit baisakhiya assembled some asciibets to say:
> 
> > at Orient Technologies at Nagpur.we were using nt server with
> 
> probably a little more than we need to know. :)
> 
> > some staff members who have started missusing the net/as there is no
> > authentication or time limit or data transfer limit to there net
> > usage.most of the time they keep on surfing xxx sites or download
> > mp3's. so now i want to know is there any free web based package on
Set a policy first. If you don't have an AUP, it is useless.
Have an AUP thats sponsored by management, signed by all staff and
enforced.

> Before I give you a solution (and there are probably others more
> qualified to do so), I think I should say that restricting web access
> through proxy rules is probably not such a good idea.  You should really
Putting technical measures in place is a good idea. This requires that
the user put in some effort to bypass the measures and then the user
cannot claim that he just clicked on a link and a pr0n site popped up.

> try setting a company-wide policy regarding this.  If people still break
> the rules, then you have better grounds for pulling them up.
> 
> Why I think blocking websites using a proxy is a bad idea:
> - You can't possibly know the domain names of all xxx sites
> - Blocking on keywords in the url would block valid sites too (think
> xxx.lanl.gov)
> - Blocking on keywords in the body of the page will also catch valid
> sites (medical sites, news sites, movie reviews, etc.)
Firewall style blocking is feasible for organizations. Block everything
and then allow access only to a restricted set of sites. When people
cannot access legitimate data, it is easier to catch (people complain)
than if they can access unwanted/disallowed data.
 
> If you're only interested in logging who's accessing what, then that is
> within your right, and would instill some amount of control.
Make logs, and use a log analyser on them. Plenty of analysers for
squid.
 
> Use Squid with acls.  There's a howto on the subject.
> 
> > linux like LiSP for managing the users and the bandwidth with proxy
> > and mail.
> 
> last I heard lisp was a programming language - the best programming
> language.
Again, you might want to buy some bundled version of Linux for support
if you have no or little unix expertise. Minimally, you will want to use
webmin (since you probably don't have much experience with *nix).
Another interesting looking proxy toolkit is zorp (python, and can proxy
lots more, but it doesn't cache, IIRC).

Devdas Bhagat

_______________________________________________
linux-india-help mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/linux-india-help

Reply via email to