Block Internet Access for certain URL's and Security groups By Mariette Knap block urls, lunch Few days ago a customer called me and asked to configure the server for limited access for several different groups of users in his organization. The customer did not want employees to browse to certain sites that have nothing to do with the daily work of those users but he wanted to allow the users to browse the sites during lunch. Pages Block Internet Access for certain URL's and Security groupsCreate a security group and add users to that groupCreate a new Firewall Policy and a Domain Name SetVerify your Firewall rule and fine tune settings In this article we will use ISA 2004 to accomplish this task. Create a security group and add users to that group In order to restrict access to certain URL's we need to create a Security group. Start the Small Business Server Server Management console from the Start Menu and click on 'Add a security group'. The 'Add a security wizard' has been started, click next. We name this security group 'SBS Restricted Internet Access' and we give it a usefull description. Click next. In this window we can add the users to the Security Group. We don't want that John Doe has access to certain URL's so we highlight John's name in the list and click add. One that is done click Next. The wizard confirms that we have added John Doe to the 'SBS Restricted Internet Access' security group. Click Next. Create a new Firewall Policy and a Domain Name Set Before we start this procedure there is something important that you need to understand before we continue. In ISA 2004 we can create Domain Name Sets and URL sets. Domain Name Sets can control all protocols and all client types, URL sets can only control connection coming from web proxy clients. This means that if you create a URL set and you use that in your rule only connections from a browser which is set to use a web proxy will be blocked and all other can pass. That is not what you would like to see so in this case we choose to create a Domain Name Set. Later in this article we will show that everything is blocked to the domains you define in a Domain Name Set. Start the ISA Server Manager and choose on the right side of the window 'Create New Access Rule'. The 'New Access Rule Wizard' has been started. We name this rule 'SBS Restrcited Internet Access'. We need to set what should happen when the conditions are met. In our case we want the rule to deny access. Click next. We set this rule to apply to all protocols. Click next. We need to set to which traffic this rule should apply to. Click add. Expand 'Networks', highlight 'Internal' and click add. Verify that the Internal network is listed and click Next. We need to specify the destination. Click add. In figure 9 we create a new Domain Name Set. Click New. In this example (see figure 10) we name our Domain Name Set 'SBS Restricted Domain' and we block 'www.smallbizserver.net'. I don't why anybody would want to block our site but anyway, this is an example. Click OK. Our Domain Name Set is listed, we highlight it and click add. After this we click Close. Our Access Destination Rule is ready, click Next. Remove the 'All Users'' group and click add. Now we need to add the users or a security group. Click New. The New User Sets Wizard is started and we add our 'SBS Restricted Internet Users'. Click next. We choose to add Windows Users and Groups. Click on Advanced. Click on the button Find Now. That will you a list. Highlight the Security Group we already created in the first part of this article and click OK. The new User Set has been created and click Next. Click add to add the User Set. The SBS Restricted Internet Users 'User Set' has been aded to our new rule. Click next. The wizard has been completed. Click Finish. ISA Server informs you that you need to save and update your settings. Click Apply. Verify your Firewall rule and fine tune settings Now we want to know if this really works. We logon to a Windows XP SP2 workstation with John Doe's credentials. Now we want to give access to those Restricted Sites during lunch hours. Open ISA Server Manager as shown in figure 1 and double click the Rule we just made and choose the Tab 'Schedule'. Click New. We have created a 'Lunch' schedule that lasts from 12:00 - 03:00. John Doe is from the Mediterranean so he takes a very long lunch!