This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Best Way To Do Our Web Filters

So, im looking for ideas on the best way to setup our UTM's for web proxy.  We are a large organisation, so looking for the best/easy way to this. 

Our web proxy is used by various internal customers, who all have different requirements.

Currently have it set in standard mode, using AD groups.

For example :-

Customer 1 by default blocks all social media.  But they want 20 staff to access Facebook and Twitter.

Customer 1 by default blocks all streaming media. But they want 20 staff to access YouTube.

The staff who need YouTube may also need Facebook but no Twitter for example so a wide mix. 

The issue is that user John Smith lets say, is a member of "All Customer 1 Staff" so it matches the 1st rule we have that he is in.

We have separate AD groups currently for YouTube, Facebook etc as we use these on TMG. 

At the moment, during testing, we have a policy rule for each customer, which says block social media and block streaming media, but how can we do it so that certain users can access certain sites, I dont mind creating rules for each one, as there is probably only 20 exceptions.  Problem is the first rule that matches the user is processed, so how do we get around that.

At the moment we use TMG so we have rules that allow Facebook and Twitter etc and block the rest and TMG processes rules as they are matched so not an issue. 



This thread was automatically locked due to age.
Parents
  • The way to do this is with Exceptions, Duncan.  Block Social Media and Streaming Media for everyone.  Make an Exception for each Backend Group going to a REGEX for the URL allowed.

    The alternative is to make more AD Security Groups where, for example, someone allowed Facebook and Twitter is not in a Group with someone allowed only Facebook.  I think the Exceptions will be clearer and easier to manage.

    Cheers - Bob

    PS you might want to take a look at Configuring HTTP/S proxy access with AD SSO.

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi,

    Thanks for the advise.  Not used the "Exceptions" before, but will look into this as a possible solution.

    I guess this is "Exceptions" and then "Coming from these users/groups" and specify the group there, with "and" and "going to these URL's" or I guess using the "Tags" will work as I currently use Tags, for different customers, as it saves time with lots of rules.

    Thanks, Duncan

    Thanks, Duncan

Reply
  • Hi,

    Thanks for the advise.  Not used the "Exceptions" before, but will look into this as a possible solution.

    I guess this is "Exceptions" and then "Coming from these users/groups" and specify the group there, with "and" and "going to these URL's" or I guess using the "Tags" will work as I currently use Tags, for different customers, as it saves time with lots of rules.

    Thanks, Duncan

    Thanks, Duncan

Children
No Data