Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Block sites by Group? And monitor web pages browsed?

Updated: 24 Mar 2011 | 18 comments
Amber's picture
0 0 Votes
Login to vote
This issue has been solved. See solution.

Hello,
I have a client running SBS 2003, and Symantec Endpoint Protection Version 11.

I have figured out how to block certain websites with Symantec. Is it possible to block by groups? Or somehow allow some users to access a site that others are blocked from?

I've also been asked if it's possible to somehow log/monitor which sites users are visiting. Not attempts to visit blocked sites, but see which sites are being accessed. Does this software provide this capability?

Thanks,
Amber
 

Comments

pete_4u2002's picture
11
Aug
2010
1 Vote +1
Login to vote

I have figured out how to block certain websites with Symantec. Is it possible to block by groups? Or somehow allow some users to access a site that others are blocked from?
If you set the firewall rules, that can be selected to group you intend to. Move the users to the groups based on rules.

I've also been asked if it's possible to somehow log/monitor which sites users are visiting. Not attempts to visit blocked sites, but see which sites are being accessed. Does this software provide this capability?
No, it does not have this feature to view the sites visited.

Amber's picture
23
Sep
2010
0 Votes 0
Login to vote

Thanks, I haven't been able

Thanks,

I haven't been able to find any instructions on how to do this.

This link in your post just leads to general help.

By groups, do you mean Active Directory groups?

I have a group I've created in AD, and I can 'add a group' in Symantec, where my rule lives, but am not sure how to make the rule work with the group...

Thanks!

Amber

Rafeeq's picture
23
Sep
2010
1 Vote +1
Login to vote

hi

You can block a site using IPS

to block in groups you need to create a host group more info here

 

How to Restrict Users to Specific Web Sites by Creating Firewall Rules for Managed Clients

http://service1.symantec.com/support/ent-security.nsf/docid/2009012915443648

 

How can I add a large number of hosts to a Host Group in Symantec Endpoint Protection Manager (SEPM)?

http://www.symantec.com/business/support/index?page=content&id=TECH91252&locale=en_US

Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq

shri1's picture
23
Sep
2010
0 Votes 0
Login to vote

You can block certin web sit

Dear Ambar/Pete,

 

Yes, you can block certain web sites for Group & with in that group you can allow some users to vist web site.

Yes, you can create a fire wall rule for that group & mention which web site you want to black for that group.

You have to create one more firewall rule & in that you have to mention Ip address for that user to allow web sites.

Regaring Log, you can create a rule to log traffice & packet for web sites for that grup & then you can view that log.

I have done & it'sworking .

 

Thanks

Shri !!

 

TomMLS's picture
24
Sep
2010
0 Votes 0
Login to vote
Hear4U's picture
24
Sep
2010
0 Votes 0
Login to vote

This thread is included in the "King for a Week" contest

Hi all,

This thread is now included in the Security Solutions Contest!  Simply do your best to solve this thread, or the others included in the contest and you could be crowned "king for the week" and win a weekly prize.  Check out the details here:

https://www-secure.symantec.com/connect/blogs/security-solutions-contest-be-king-week

 

Best,

Eric

Subscribe to the upcoming Security Newsletter - Log in, visit your profile, and click on "Newsletter Subscriptions!"

Fatih Teke's picture
24
Sep
2010
2 Votes +2
Login to vote

Hello,

Hello,I created a article about it.

https://www-secure.symantec.com/connect/articles/how-block-internet-address-sep-manager-firewall-rule

Best Regards.

Fatih

 Everything works better when everything works together.

AravindKM's picture
25
Sep
2010
0 Votes 0
Login to vote

Refer this video . Allow and

Refer this video .

Allow and Block websites using Symantec Endpoint Protection Firewall

It will show you how to allow/block the sites using SEP.Remember that if you want to use this feature in all the clients which the website to be block should have Network Threat Protection Installed

In SEPM we can apply the policy in Group Level only.If you want to allow some user to see these websites and to other to block,create two groups.For first group assign the policy which will not block the sites and for the second create a block policy and assign.Move the users/computers to the first group who should use these sites and move the other users to second group who should not use these sites.

 

SEPM/SEP do not having the capability of tracking the sites visited.  

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

Mohammad Altaf Khan's picture
25
Sep
2010
0 Votes 0
Login to vote

Just Make Sure Enable Log

Just to make sure Enable Write Logs on Taffic Log

goto

policy>firewall>Add a Firewall Policy> rules >Add Blank Rule > in Application add iexporer and other internet Browser >host add websites >Action block> Logging write to Traffic log

  

Amber's picture
03
Nov
2010
0 Votes 0
Login to vote

Hello, Originally I was using

Hello,

Originally I was using 'Intrusion Prevention' and was blocking forbidden sites (eg. facebook). It worked well, but I wanted to know how to allow certain users to access these sites.

So I followed your instructions and removed the rules I had created under 'Intrusion Prevention' and added a new firewall policy.

I'm sure I've followed your instructions but the rule doesn't seem to work (users can all access the sites I've blocked).

I'm pretty sure the problem lies with my groups.

I've created 2 groups - one 'All users except Managers' and one 'Managers'. I used the 'Import AD or LDAP Users' method of adding users to these 2 groups.

All of the users I want are correctly listed in one of the two groups, but the firewall policy doesn't seem to affect them.

I assume I'm missing a step somewhere??

Thanks,

Amber

 

Vikram Kumar-SAV to SEP's picture
03
Nov
2010
0 Votes 0
Login to vote

So the firewall rules are not

So the firewall rules are not working on the groups??

Is the firewall policy shared ? or have you created 2 policies 1 for managers other for the non manager group?

Can post the screenshot of the rule?

Amber's picture
24
Nov
2010
0 Votes 0
Login to vote

Hi, Attached is a screenshot

Hi,

Attached is a screenshot of the rule.

Thanks :)
Amber

printscreen of rule.jpg
Thomas K's picture
24
Nov
2010
0 Votes 0
Login to vote

Did you create the rule in

Did you create the rule in the FW rule list? I think Vikram  means a screenshot like this one below.

 

Amber's picture
24
Nov
2010
0 Votes 0
Login to vote

Yes, sorry. Attached is that

Yes, sorry.

Attached is that screen shot...

 

Amber

printscreen of rule2.jpg
Vikram Kumar-SAV to SEP's picture
24
Nov
2010
0 Votes 0
Login to vote

This is the default rule I

This is the default rule I cannot see the rule for blocking the Websites..