Deny outbound on ports 80 and 443 at the firewall to force access through a proxy server that uses domain credentials or radius server. Squid on a FreeBSD box works very well for that.
On Wed, May 21, 2008 at 10:36 PM, Angus Scott-Fleming <[EMAIL PROTECTED]> wrote: > I have one client with one shared XP Pro computer where we want to allow only > one user to access the Internet, but for other reasons I can't enforce network > logins -- the system has some unique software that needs admin rights. But > the > department head want to have only himself accessing the Internet. In Internet > Explorer I can do this by passwording Content Controls. Does anyone know of a > way to do this in Firefox, Opera, and other browsers? Since the system is > shared with admin rights, I can't stop the users from bringing in a USB stick > with Firefox Portable on it, so I need a way to block all access except when > the dept head enters his password. > > This is a standalone system, NOT part of the domain -- it's in the maintenance > building and not subject to my control except from providing Internet access > through our network. The firewall is IPCop, and it's already set up for the > rest of the site to permit access only to certain specified sites from most > computers, but this one is unique in that sometimes it needs wide-open access, > but the rest of the time it needs to be blocked. I can't enable that sort of > blocking on the network firewall without enabling it for all computers, and > that won't fly. > > Just looking for ideas here ... > > -- > Angus Scott-Fleming > GeoApps, Tucson, Arizona > 1-520-290-5038 > +-----------------------------------+ > > > > > ~ Upgrade to Next Generation Antispam/Antivirus with Ninja! ~ > ~ <http://www.sunbelt-software.com/SunbeltMessagingNinja.cfm> ~ > ~ Upgrade to Next Generation Antispam/Antivirus with Ninja! ~ ~ <http://www.sunbelt-software.com/SunbeltMessagingNinja.cfm> ~
