website breach in the network!!!

General Network security, firewalls, port filtering/forwarding, wireless security, anti-spyware, as well as spam control and privacy discussions.
Post Reply
theo76
New Member
Posts: 8
Joined: Wed Nov 21, 2007 2:52 pm

website breach in the network!!!

Post by theo76 »

Hi all,

I have a d-link router and I deny access to several sites. For some reason or another some students have been gaining acces to websites I have blocked using iproxy. Is there a way I can block iproxy from the my users?

Need some professional help Please!!!!

A concerned administrator
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

Sounds like a "school"? How large of a network? Is there a domain controller in there, active directory? Any other content filtering going on? Websense is common in schools. Any blocking of the anon proxy services?
MORNING WOOD Lumber Company
Guinness for Strength!!!
theo76
New Member
Posts: 8
Joined: Wed Nov 21, 2007 2:52 pm

Post by theo76 »

I work in a small high school with 200 students and about 120 pc's. I have one main d-link router. I also have a windows 2000 server along with a dhcp server. I'm quite new to this layout so I may need some professional help. I'm sure the win2000 server has a domain controller and possitive it has an active directory.

any suggestions?
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

A big network like that...I'd not want a home consumer grade router doing the job. Have you looked at Websense?
MORNING WOOD Lumber Company
Guinness for Strength!!!
User avatar
chpalmer
Advanced Member
Posts: 559
Joined: Sun Oct 13, 2002 3:52 pm
Location: Kitsap co Wa

Post by chpalmer »

http://www.untangle.com/ might be worth a look for you...

What model is the Dlink? Is it a commercial grade unit?
Never take any crap off an inanimate object!!

Never send email to this address: spam@euclidian.com. This is a spam trap and everyone sending any email to this address will be blacklisted.
lucifercipher
Member
Posts: 22
Joined: Sun Jul 19, 2009 11:47 am

Post by lucifercipher »

Well , you didnt give enough info about your Dlink router. So im assuming its just acting as a NAT device aka Internet sharing device for your school. If you really want to force your users / restrict them then just get a single linux desktop , use iptables to force all HTTP requests through it while running dhcpd. You can use HTTP Cache SQUID http://www.squid-cache.org 's content and URL filtering to accomplish this task. That way your users will also get cache hits and end up having nicer browsing experience.
Post Reply