Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

December 27, 2005 12:00 AM

Configuring Intranet Access Without Giving Internet Access

Windows IT Pro
InstantDoc ID #48516
Rating: (6)

I have users on my Windows network who need to access an intranet site. However, they don't need to access the Internet, and management wants me to prevent them from doing so. Restricting access to the iexplore.exe file on the local workstations isn't an option because the file is needed to run the intranet site. We have just a basic firewall that can restrict Internet access only according to IP address, and I don't want to assign static IP addresses to these clients. How can I configure intranet access without allowing Internet access?

If you don't want to block Internet access at the firewall, you can create an IP Security Policy and use Group Policy to push it to the appropriate workstations. (Note that IP Security Policies aren't the same as IPsec. Windows implements IPsec through IP Security Policies, but IPsec is only part of IP Security Policies.)

IP Security Policies are composed of rules, and each rule has a filter list and an action. The filter list defines the packets for which Windows should execute the specified action. You can choose to allow the filtered packets, block the packets, or establish an IPsec connection to protect the packets. In the latter case, you create an IP Security Policy with two rules. The first rule blocks all outgoing connections to port 80 and port 443. The second rule permits outgoing port 80 and port 443 connections if the destination address is within your LAN's subnets.

The order of the rules doesn't matter—Windows automatically applies the most specific rule to each packet. Note, however, that this solution isn't user specific. IP Security Policies are computer-specific settings that you define under the Computer Configuration section of a Group Policy Object (GPO). Therefore, make sure you link the policy to an organizational unit (OU) or group comprised of the restricted users' computers—not their user accounts.

Be aware that the policy described above will break Windows Update. If you deploy updates through Windows Update, you need to add the appropriate DNS names of Microsoft's Windows Update sites to the permit rule's filter list so that the computers will continue to apply security updates. The sites Windows Update contacts are

  • http://windowsupdate.microsoft.com
  • http://*.windowsupdate.microsoft.com
  • https://*.windowsupdate.microsoft.com
  • http://download.windowsupdate.com
  • http://*.download.windowsupdate.com
  • http://*.windowsupdate.com
  • http://wustat.windows.com
  • http://ntservicepack.microsoft.com

Note that this list can change at any time.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.