Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

November 11, 2008 12:00 AM

Q: How can I prevent Microsoft Internet Explorer (IE) users from accessing certain websites without deploying special software?

Windows IT Pro
InstantDoc ID #100613
Rating: (0)
A: You can use IE’s built-in Content Advisor to prevent users from accessing specific websites. Content Advisor offers an interesting alternative to investing in a third-party solution to block URL access, or to blocking access on your organization’s Internet-facing firewalls, proxy servers, or content scanning servers.
    
You can access Content Advisor’s settings from the Content tab in IE’s Internet Options. If you click Enable in the Content Advisor section, IE will open the Content Advisor configuration options. To prohibit access to a given URL, click the Approved Sites tab, enter the URL in the Allow this website box , and click the Never button. This action will add the site to the list of prohibited websites, as shown in Figure 1 for www.contoso.com and www.toysrus.com. Note that enabling the Content Advisor setting will also require you to set a supervisor password.

You can also centrally control Content Advisor settings for IE users in your Windows domain using Group Policy Object (GPO) settings. You can find the Content Advisor settings in Group Policy Editor (GPE) in the User Configuration\Windows Settings\Internet Explorer Maintenance\Security container. The Content Advisor settings are located under the Security Zones and Content Ratings GPO.

Configuring the Content Advisor GPO setting is slightly different from how you configure other GPO settings: Instead of configuring the Content Advisor settings in GPE directly, you must import them from a computer that’s already configured. GPE walks you through the process of importing the Content Advisor settings, as shown in Figure 2.

Note that there are ways around this block, such as looking at cached search engine results. Also, Content Advisor settings don’t stop a user from loading a different browser to look at blocked sites. If you’re using Windows Vista’s Home Basic, Home Premium, or Ultimate versions, consider using Vista’s built-in parental controls to prevent users from viewing specific websites instead

Another way to block access to specific websites is by using the little-known Route command. The Route command is available on every Windows system and can be used to modify the local IP network routing table. When you type a URL in your browser, Windows uses the local routing table as a network map to determine where to send the packet. In most cases, the routing table directs the packet to a default gateway, which then sends it out to another network or the Internet. Using the Route command, you can configure the routing table so that Windows will send the packets that are addressed to certain websites or IP addresses to a dead end. To the user it will appear the website doesn’t exist or isn’t accessible.

To use Route in this way, you must know the IP address of the website to which you want to block access. You must also know an IP address within your local network subnet that isn’t in use to use as the “dead end” IP address. For example, if the IP address of the website you want to block access to is 13.12.11.10, and the dead-end IP address on your local subnet is 192.153.34.33, then you would use the following command:

route -p add 13.12.11.10 mask 255.255.255.255 192.153.34.33

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.