Search This Blog

Friday, November 25, 2011

Block a single computer from surfing on the Internet

To configure a single computer follow these steps:

Configuring IP Filter Lists and Filter actions
  1. Open an MMC window (Start > Run > MMC).
  2. Add the IP Security and Policy Management Snap-In.
  1. In the Select which computer this policy will manage window select the local computer (or any other policy depending upon your needs). Click Close then click Ok.
  1. Right-click IP Security Policies in the left pane of the MMC console. Select Manage IP Filter Lists and Filter Actions.
  1. In the Manage IP Filter Lists and Filter actions click Add.
  1. In the IP Filter List window type a descriptive name (such as HTTP, HTTPS) and click Add to add the new filters.
  1. In the Welcome window click Next.
  2. In the description box type a description if you want and click Next.
  1. In the IP Traffic Source window leave My IP Address selected and click Next.
  1. In the IP Traffic Destination window leave Any IP Address selected and click Next.
  1. In the IP Protocol Type scroll to TCP and press Next.
  1. In the IP Protocol Port type 80 (for HTTP) in the To This Post box, and click Next.
  1. In the IP Filter List window notice how a new IP Filter has been added. Now, if you want, add HTTPS (Any IP to Any IP, Protocol TCP, Destination Port 443) in the same manner.
  1. Now that you have both filters set up, click Ok.
  1. Back in the Manage IP Filter Lists and Filter actions review your filters (you can add or remove more filters later). Now we'd like to add a new filter that will define the INTRANET web traffic. Again, click Add.
  1. Again, give the new filter an appropriate name - for example - Intranet, and then proceed to configuring the filter by clicking Add.
  1. In the IP Traffic Source window leave My IP Address selected and click Next.
  2. In the IP Traffic Destination click the drop-down list and select the type of destination. For example, if you only want to allow web traffic for one specific Intranet web server called SERVER200, choose A Specific DNS Name.
Then, in the Host Name box type SERVER200 and click Next.
If you want to allow web traffic for an entire internal subnet such as 192.168.0.0/24, select A Specific IP Subnet, and type the Network ID and Subnet Mask for the required subnet. Click Next.
  1. Back in the IP Filter list add any other filter you want, and finally click Ok.

No comments: