• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Discussion about article on site blocking

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> Access Policies >> Discussion about article on site blocking Page: [1] 2 3 4   next >   >>
Login
Message << Older Topic   Newer Topic >>
Discussion about article on site blocking - 27.Apr.2005 3:13:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
This thread is for discussing Greg Mulholland's article on using the ISA firewall for site blocking at http://isaserver.org/articles/2004firewallblocklist.html

Thanks!
Tom

[ April 27, 2005, 03:25 PM: Message edited by: tshinder ]
Post #: 1
RE: Discussion about article on site blocking - 27.Apr.2005 4:42:00 PM   
StageElectrics

 

Posts: 20
Joined: 11.Apr.2005
From: United Kingdom
Status: offline
Hi there!

Can you tell me how can I make the ISA 2004 to scan each web page for keywords and block the page if any keywords match the black list of keywords. For example I want to block every page that has the "teen" word in it. Is it possible?

Thanks
Stage Electrics

(in reply to tshinder)
Post #: 2
RE: Discussion about article on site blocking - 27.Apr.2005 5:09:00 PM   
rjodwyer

 

Posts: 13
Joined: 16.Feb.2005
From: Melbourne, Australia
Status: offline
Hey,

Great article, have been waiting for how to configure this on ISA2004 for some time.

What I would like to know is, is it possible to allow some users past the blacklist? if the ISA is in domain, can i tell it that the rule applies to domain users only? etc?

Many thanks,
Ryan O'Dwyer

(in reply to tshinder)
Post #: 3
RE: Discussion about article on site blocking - 27.Apr.2005 5:15:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
quote:
Originally posted by Stage Electrics:
Hi there!

Can you tell me how can I make the ISA 2004 to scan each web page for keywords and block the page if any keywords match the black list of keywords. For example I want to block every page that has the "teen" word in it. Is it possible?

Thanks
Stage Electrics

Hi Stage,

Yes, you can use the HTTP Security Filter signatures to do this. I'll put this on the article list for upcoming articles.

Thanks!
Tom

(in reply to tshinder)
Post #: 4
RE: Discussion about article on site blocking - 27.Apr.2005 5:17:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
quote:
Originally posted by Ryan O'Dwyer:
Hey,

Great article, have been waiting for how to configure this on ISA2004 for some time.

What I would like to know is, is it possible to allow some users past the blacklist? if the ISA is in domain, can i tell it that the rule applies to domain users only? etc?

Many thanks,
Ryan O'Dwyer

Hi Ryan,

You bet. You can create the rule to apply to all user *except* the group in question, on the Users tab of the rule.

This will turn the rule into an authenticated access rule, so you'll have to be careful where to place it in relation to your anonymous access rules.

HTH,
Tom

(in reply to tshinder)
Post #: 5
RE: Discussion about article on site blocking - 27.Apr.2005 6:46:00 PM   
denizyalcin

 

Posts: 122
Joined: 19.Jan.2005
From: Turkey
Status: offline
Hi all,

I'm already using such a URL filter but instead of using just one massive URL block I do categorize my filters. I know that it will take a huge time to have a succesful filter but I'm not going to analyze and filter those unproductive site visits for a long time.

My goal by doing categorized filter lists is to show specialized warnings to the users. It will especially be useful for our goverment users. For some types of websites I need to show official warnings to the employees and for other types I need specified warnings which would embarrass and warn them [Wink] This way, I think I could force them to use the internet in a more productive way.

I haven't prepared those warning pages yet but I would like to get those pages from a local drive. There is a checkbox in the "Action" tab of Access Policy properties which says "Redirect HTTP requests to this Web page". Is it possible to point this webpage to a local file on the ISA box ?

(in reply to tshinder)
Post #: 6
RE: Discussion about article on site blocking - 27.Apr.2005 11:32:00 PM   
isawader

 

Posts: 420
Joined: 27.Apr.2005
Status: offline
If I have a URL set with 500 entries, how will this affect the ISA's performance. I would imagin ISA needs to go through each URL entry for every outgoing traffic and do authentication on top of it. Hopefully ISA uses something like hash tables for searching.

(in reply to tshinder)
Post #: 7
RE: Discussion about article on site blocking - 28.Apr.2005 1:03:00 AM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi ISA,

I've tested with over 100,000 entries will little effect on performance.

HTH<
Tom

(in reply to tshinder)
Post #: 8
RE: Discussion about article on site blocking - 28.Apr.2005 5:25:00 AM   
amitrkothari

 

Posts: 3
Joined: 1.Mar.2005
Status: offline
To block the specific keywords, you can use Signature configuration in HTTP Filtering... I tried with all the messenger.

I start the Etherreal and capture the ongoing traffic URL. Search any keyword and block it in Signature section.

This way you can block Rediff, Hotmail, Yahoo attachments also.

Amit kothari
TATA BPO
Network Administrator

(in reply to tshinder)
Post #: 9
RE: Discussion about article on site blocking - 2.May2005 11:43:00 PM   
helfirex

 

Posts: 86
Joined: 2.Jan.2004
Status: offline
I would be very intrested in using the http filter to block specific words. Look forward to the article tom.

Chris

(in reply to tshinder)
Post #: 10
RE: Discussion about article on site blocking - 3.May2005 7:46:00 AM   
huma

 

Posts: 1
Joined: 25.Apr.2005
From: pakistan
Status: offline
hi

i want to block any web page thats URL contain the keyword "sex" any where in it (in start, mid or end of URL) is it possible in isa server 2000 and isa server 2004 , if it is so tell me the whole procedure

(in reply to tshinder)
Post #: 11
RE: Discussion about article on site blocking - 3.May2005 11:16:00 AM   
tahsin

 

Posts: 1
Joined: 19.Jan.2005
Status: offline
Hello,
How I can apply these applications on ISA Server 2000. Thank you.

(in reply to tshinder)
Post #: 12
RE: Discussion about article on site blocking - 4.May2005 5:12:00 PM   
Guest
Hi, great article ! Have a question though, am i doing something wrong ?

Take for example the URL "fateback.com".
Through the IE you can access the site both by "http://www.fateback.com" and "http://fateback.com". However, by blocking "http://fateback.com" y can still access it by using "http://www.fateback.com"

Am i doing something wrong or is it supposed to work like this ?

I've tried blocking "http://*.fateback.com" and it works, but is this how it is suppossed to be done ?

ps: This doesnt happen only with that address, i've tried it with many on the blocked lists from the article.

Best regards,
Alan

(in reply to tshinder)
  Post #: 13
RE: Discussion about article on site blocking - 18.May2005 10:01:00 AM   
Guest
Is there any way to block via IP and except via IP instead of user name?

(in reply to tshinder)
  Post #: 14
RE: Discussion about article on site blocking - 18.May2005 10:21:00 AM   
Guest
Forget that last post ... Got it.

You can get exceptions by looking at the rule after it is created but not before ... still keeps throwing me in comparison to ISA2K.

(in reply to tshinder)
  Post #: 15
RE: Discussion about article on site blocking - 24.May2005 5:56:00 PM   
gtjr92

 

Posts: 4
Joined: 22.Oct.2004
From: CIncinnati
Status: offline
How can i import these lists into ISA Server 2000??
Thanks

(in reply to tshinder)
Post #: 16
RE: Discussion about article on site blocking - 6.Jun.2005 5:39:00 AM   
cybernard

 

Posts: 23
Joined: 5.Mar.2005
Status: offline
I have followed http://isaserver.org/articles/2004firewallblocklist.html article using same xml block lists, but for some reason it does not work ??

(in reply to tshinder)
Post #: 17
RE: Discussion about article on site blocking - 6.Jun.2005 6:36:00 AM   
bimbis

 

Posts: 4
Joined: 6.Jun.2005
Status: offline
Hi,
Check this out i have tried this http://blacklists.w.interia.pl/index_b2004.htm

it works

Bimbis

(in reply to tshinder)
Post #: 18
RE: Discussion about article on site blocking - 6.Jun.2005 6:45:00 AM   
ISA_NL

 

Posts: 15
Joined: 26.May2005
Status: offline
But how does this works for isa2000,.
I cant get it in my isa 2000 environment.

plz help

(in reply to tshinder)
Post #: 19
RE: Discussion about article on site blocking - 7.Jun.2005 5:53:00 AM   
ISA_NL

 

Posts: 15
Joined: 26.May2005
Status: offline
Tshinder,

Plz help us with importing the blacklist into isa 2000 , i think very much peoople want that...

PLz reaction,

GreetZ isa_nl

(in reply to tshinder)
Post #: 20

Page:   [1] 2 3 4   next >   >> << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> Access Policies >> Discussion about article on site blocking Page: [1] 2 3 4   next >   >>
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts