SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > Operating Systems > Windows NT/2000/2003
User Name
Password


GroupPolicy IE Lockdown

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes

  #1  
Old 01-10-2005, 05:36 PM
jnalpak Offline
Registered User
 
Join Date: Mar 2003
Location: New York City
Posts: 172
GroupPolicy IE Lockdown

Im looking to lockdown a laptop. I have set what i wanted to on the GP and it applies correctly, my only question is the following.

How do i setup InternetExplorer to ONLY work on ONE SITE. for instance I want the user to open up and only run http://my.citrixsecuregateway.com and then from there run published apps.

can this be done and if so please help.
thanks
__________________
"I was raised by a cup of coffee" -Homsar
Reply With Quote

  #2  
Old 01-12-2005, 06:05 AM
RoSpider's Avatar
RoSpider Offline
Registered User
 
Join Date: Sep 2004
Location: Romania
Posts: 122
The following method allows you to lock in Internet Explorer 5 to a defined group of web addresses. By changing the proxy settings in Internet Explorer, you will only be able to access those sites that you allow.

STEP 1 From the menu bar, select Tools and Internet Options. Click on the tab labeled Connections.

STEP 2 At the bottom of the Connections panel is a box labeled LAN Settings. Click on this box.

STEP 3 In the box labeled Local Area Network (LAN) Settings, go to the section labeled Proxy Server and check the box labeled Use a Proxy Server. This will "ungrey" the rest of the settings.

STEP 4 Click on the button labeled Advanced to open the panel labeled Proxy Settings.

STEP 5 In the section labeled Servers, under Proxy Address to use, enter the address 127.0.0.1 into the box next to HTTP: This provides a "dummy" address that will prevent the browser from going out to the Internet. You can also use a message like "Online Catalog".

STEP 6 At the bottom of the section labeled Servers, check the box labeled Use the same proxy server for all protocols. This will automatically complete the other boxes with what you entered in Step 5. This setting will prevent users from accessing FTP and Gopher sites through the web broswer.

STEP 7 In the section labeled Exceptions, enter the domains of the addresses that you DO want patrons to access. For example, I would enter "web2.tln.lib.mi.us" to allow access to our web catalog. Follow the instructions and make sure to use semi-colons between entries if you need to enter more than one domain.

STEP 8 Click on the OK boxes until you return to Internet Explorer. Now test your settings by browsing to your site that you entered in the exceptions. Now, try surfing to a site that is not allowed - the browser should not be able to "find" the site.

If you want to allow access to a single domain [i.e. all ".gov" sites] just enter the domain name [e.g.: gov, edu, etc.] into the exceptions box with a wildcard[*] and a dot [.]before the domain name For example, *.gov This will allow access to all sites ending in ".gov" but no other domains. You can be as general or specific as you want.

However many of the online databases use multiple servers with multiple domain names to present the information. Try using a more general domain entry in the exceptions box. For example, instead of using "infotrac.galegroup.com/itweb/lom_waterfordtpl", use the more general "galegroup.com" - this will allow the browser to access all sub-domains at "galegroup.com".

Microsoft provides an alternative method that makes use of the Content Advisory system to limit access. You can view the Knowledge Base article at http://support.microsoft.com/kb/q267930/#kb1.
__________________
AMD Athlon XP 2500+ Barton
ASUS A7N8X mobo
512MB DDR400 Synch DRAM
80GB Western Digital Caviar 7200rpm 8MB Cache IDE HDD
20GB Western Digital Protege 5400rpm 2MB Cache IDE HDD
MSI GeForce MX440 64MB 8x
ASUS CDRW Drive 52x/32x/52x
BENQ CD-ROM Drive 52x
17" CRT Relisys TE770 Monitor
Windows XP Proffesional SP 1a
Reply With Quote

  #3  
Old 01-12-2005, 09:23 AM
jnalpak Offline
Registered User
 
Join Date: Mar 2003
Location: New York City
Posts: 172
Thumbs up

great work, that helped me lots!!
__________________
"I was raised by a cup of coffee" -Homsar
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
GP Startmenu Lockdown jnalpak Windows NT/2000/2003 0 10-22-2004 11:58 AM



All times are GMT -5. The time now is 09:18 PM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.