This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web Filter Policy based on Computer Name or IP

Hello,   I'm using UTM 9.355-1 at home.    I currently use the web filtering feature, and I noticed that I can assign users or groups to a policy, but is there a way I can assign policies to computers or IP address?

I currently have IP reservations enabled for my machines and have them named.     What I'm trying to do, is to create a policy for my daughter's internet use.  To block sites at certain times.  etc..

Right now what I am doing for it, is for the allowed networks to put the the computers in a group, and assign the group to the allowed networks, and remove the "Internal network from the firewall setting, (since the web filter bypasses the firewall out rule) so if I delete the computer from the web filter allowed networks, No internet access for that machine.

Is there another way for me to make a policy for a specific machine.  Short of making an Active Directory or LDAP server.

Thanks



This thread was automatically locked due to age.
Parents
  • Yes, Mike, there is.

    In 'Web Filtering', you can configure the Base Profile.  In 'Web Filtering Profiles', you can configure additional profiles.

    An access qualifies for a Profile based on it's IP address.  The Profiles are considered in order ending with the Base Profile.  Once an access qualifies for a Profile, no further Profiles are considered.  This is the universal rule for all ordered lists in WebAdmin.

    So, if your home network is 172.21.1.0/24 and your daughter's device has an IP of 172.21.1.55, select "Internal (Network)" or your group for 'Allowed Networks' in the Base Profile and the Host object for 172.21.1.55 for 'Local Networks' in the profile configured in 'Web Filtering Profiles'.  In that way, your daughter's access will be captured by the profile and not considered for the Policy in the Base Profile.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Yes, Mike, there is.

    In 'Web Filtering', you can configure the Base Profile.  In 'Web Filtering Profiles', you can configure additional profiles.

    An access qualifies for a Profile based on it's IP address.  The Profiles are considered in order ending with the Base Profile.  Once an access qualifies for a Profile, no further Profiles are considered.  This is the universal rule for all ordered lists in WebAdmin.

    So, if your home network is 172.21.1.0/24 and your daughter's device has an IP of 172.21.1.55, select "Internal (Network)" or your group for 'Allowed Networks' in the Base Profile and the Host object for 172.21.1.55 for 'Local Networks' in the profile configured in 'Web Filtering Profiles'.  In that way, your daughter's access will be captured by the profile and not considered for the Policy in the Base Profile.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data