DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Exclude all but 2 websites - challenge!
- cpcnw
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 21
- Thank yous received: 0
02 Nov 2015 15:16 #84656
by cpcnw
Exclude all but 2 websites - challenge! was created by cpcnw
Hi All,
I have been asked the following; can you apply rules to a 2830n v2 that will block all websites apart
from 2 specific sites?
I had previously blocked reception from surfing the net by putting an incorrect proxy in the browser.
However I am now told that the two reception staff actually need two sites which are vital to doing
their job.
I suspect that I would need the MAC address of the two machines concerned [although I could set
static IP's] and look at the filters.
If anyone has actually done anything like this would appreciate some pointers!
Or are there any online resources [tutorials / step by steps] that would help me?
Thanks!
I have been asked the following; can you apply rules to a 2830n v2 that will block all websites apart
from 2 specific sites?
I had previously blocked reception from surfing the net by putting an incorrect proxy in the browser.
However I am now told that the two reception staff actually need two sites which are vital to doing
their job.
I suspect that I would need the MAC address of the two machines concerned [although I could set
static IP's] and look at the filters.
If anyone has actually done anything like this would appreciate some pointers!
Or are there any online resources [tutorials / step by steps] that would help me?
Thanks!
Please Log in or Create an account to join the conversation.
- sicon
- Offline
- Contributor
Less
More
- Posts: 642
- Thank yous received: 0
02 Nov 2015 15:38 #84660
by sicon
Replied by sicon on topic Re: Exclude all but 2 websites - challenge!
You could add the 2 mac addresses or static IPs to a firewall filter policy that blocks all WAN>LAN Traffic for Services HTTP and HTTPS and the source as the 2 machines with the rule as "Block if no further match"
Underneath you then need to create an Allow (pass immediately) rule with the IP addresses of the websites that are allowed for those machines.
Draytek routers are IP based not application based firewalls so this sort of thing is quite messy.
Failing that you need to looking to proper Web filtering
Underneath you then need to create an Allow (pass immediately) rule with the IP addresses of the websites that are allowed for those machines.
Draytek routers are IP based not application based firewalls so this sort of thing is quite messy.
Failing that you need to looking to proper Web filtering
Please Log in or Create an account to join the conversation.
- cpcnw
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 21
- Thank yous received: 0
03 Nov 2015 07:42 #84666
by cpcnw
Can you make recommendations here?
Replied by cpcnw on topic Re: Exclude all but 2 websites - challenge!
Failing that you need to looking to proper Web filteringsicon wrote:
Can you make recommendations here?
Please Log in or Create an account to join the conversation.
- voodle
- Offline
- Big Contributor
Less
More
- Posts: 1139
- Thank yous received: 0
03 Nov 2015 10:55 #84670
by voodle
Replied by voodle on topic Re: Exclude all but 2 websites - challenge!
So, the way I would do it is use the DNS filter:
Make IP objects for the PCs
Make two keyword objects for the sites to be allowed
Make a CSM - URL Content Filter Profile with those two sites set up with an action of Pass (=whitelist)
Make a DNS Filter Profile entry that uses that URL content filter profile
Make a Firewall - Filter Rule entry under #2 Default Data Filter:
Direction: WAN to LAN
Source IP: those two IP objects
Destination IP: Any
Service Type: Any
Action: Pass Immediately (because this links the CSM, not IP filtering so we just pass it here and link the CSM entries in the filter rule)
URL Content Filter: that profile
DNS Filter: that profile
Now with that rule set up, those two IPs will only be allowed to get DNS for those two sites, the router will just give its own IP and a block page for every other DNS lookup
Make sure that the PCs are using an internet DNS server or a DNS server other than the router, because of a weird limitation of how the DNS filtering etc works on the router - if they use the router's IP for DNS, it applies the settings from CSM - DNS Filter Profile - DNS Filter Local Setting instead of what the filter rule does
Make IP objects for the PCs
Make two keyword objects for the sites to be allowed
Make a CSM - URL Content Filter Profile with those two sites set up with an action of Pass (=whitelist)
Make a DNS Filter Profile entry that uses that URL content filter profile
Make a Firewall - Filter Rule entry under #2 Default Data Filter:
Direction: WAN to LAN
Source IP: those two IP objects
Destination IP: Any
Service Type: Any
Action: Pass Immediately (because this links the CSM, not IP filtering so we just pass it here and link the CSM entries in the filter rule)
URL Content Filter: that profile
DNS Filter: that profile
Now with that rule set up, those two IPs will only be allowed to get DNS for those two sites, the router will just give its own IP and a block page for every other DNS lookup
Make sure that the PCs are using an internet DNS server or a DNS server other than the router, because of a weird limitation of how the DNS filtering etc works on the router - if they use the router's IP for DNS, it applies the settings from CSM - DNS Filter Profile - DNS Filter Local Setting instead of what the filter rule does
Please Log in or Create an account to join the conversation.
- sicon
- Offline
- Contributor
Less
More
- Posts: 642
- Thank yous received: 0
04 Nov 2015 14:43 #84679
by sicon
Barracuda Networks
Replied by sicon on topic Re: Exclude all but 2 websites - challenge!
cpcnw wrote:
Failing that you need to looking to proper Web filteringsicon wrote:
Can you make recommendations here?
Barracuda Networks
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek