DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Block Windows AD group from internet
- ceefla
- Topic Author
- Offline
- New Member
Less
More
- Posts: 2
- Thank yous received: 0
06 Sep 2017 15:01 #89543
by ceefla
Block Windows AD group from internet was created by ceefla
Using a 2830 router for our office and would like to block internet access for a specific group of users.
Users do not currently need to login to the router to get internet and I don't want to change this.
Is it possible to block a Windows group from access just using my router or do I need to add a separate firewall that can achieve this?
Thanks,
Colin
Users do not currently need to login to the router to get internet and I don't want to change this.
Is it possible to block a Windows group from access just using my router or do I need to add a separate firewall that can achieve this?
Thanks,
Colin
Please Log in or Create an account to join the conversation.
- mbames
- Offline
- Member
Less
More
- Posts: 326
- Thank yous received: 0
06 Sep 2017 18:23 #89544
by mbames
Replied by mbames on topic Re: Block Windows AD group from internet
Pretty sure the 2830 has no concept or AD connectivity, so you would need to install a firewall like device which does - suspect that pfsense would do the job for you.
You'd need to ensure that any 'smart' users couldn't bypass the pfsense box by changing their default gateway to the 2830. Or that you prevent all users from modifying network setting/IE proxy settings so they use what ever is forced out by the AD groups.
Thinking about it, the quick option would be to say for the AD group you don't want to have internet is to give them a duff default gateway (assuming you have a simple network) or force them to have a different proxy.pac file (assuming they don't have local machine permissions to change).
You'd need to ensure that any 'smart' users couldn't bypass the pfsense box by changing their default gateway to the 2830. Or that you prevent all users from modifying network setting/IE proxy settings so they use what ever is forced out by the AD groups.
Thinking about it, the quick option would be to say for the AD group you don't want to have internet is to give them a duff default gateway (assuming you have a simple network) or force them to have a different proxy.pac file (assuming they don't have local machine permissions to change).
Please Log in or Create an account to join the conversation.
- ceefla
- Topic Author
- Offline
- New Member
Less
More
- Posts: 2
- Thank yous received: 0
07 Sep 2017 14:48 #89565
by ceefla
Replied by ceefla on topic Re: Block Windows AD group from internet
Thanks - yes, I like your suggestion about the duff proxy as it really does prevent a simple requirement becoming out of hand in terms of money and time spent.
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek