home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Networking and Internet
Ask a Tech Support Question (free)!

ICS deny access to one computer

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1129
Discussions: 204,507, Posts: 2,419,430, Members: 249,926
Old September 7th, 2002, 01:16 AM   Digg it!   #1 (permalink)
Ultimate Member
 
skuz's Avatar
 
Join Date: Oct 2001
Location: Quebec, Canada
Posts: 1,784
ICS deny access to one computer

Is it possible when using ICS to deny web access to a particular computer without preventing it from using the local network ?
skuz is offline   Reply With Quote
Old September 7th, 2002, 01:49 AM     #2 (permalink)
Member
 
Join Date: Sep 2002
Location: Wyoming
Posts: 64
Send a message via Yahoo to Elite_Monkey
hhmmm i guess i don't know,,,well good luck
Elite_Monkey is offline   Reply With Quote
Old September 7th, 2002, 03:39 AM     #3 (permalink)
addicted
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 6,103
Yes.

One idea... if you only have one subnet then add a ficticious Default Gateway IP address to that computer. Then it won't know how to get out of the LAN.

Another idea, set the IP address manually on this computer and don't set a default Gateway IP address. An IP like 192.168.0.250 so it is unlikely ICS willl ever try to assign that IP address somewhere.

Last edited by DVNT1 : September 7th, 2002 at 03:42 AM.
DVNT1 is offline   Reply With Quote
Old September 7th, 2002, 09:48 AM     #4 (permalink)
Ultimate Member
 
skuz's Avatar
 
Join Date: Oct 2001
Location: Quebec, Canada
Posts: 1,784
Yes, that would work, but temporarily, since the person there knows the basics of TCP/IP configuration. I would prefer doing something on the server/gateway (Win2kpro) so he cannot fix it himself.

The goal is to block this person against his will. Sure I could buy a Cisco router and make an access list, but that's a bit expensive.
skuz is offline   Reply With Quote
Old September 7th, 2002, 10:02 AM     #5 (permalink)
mickwish
 
Posts: n/a
Don't know if this would work, 'cause I don't know enough about domains and win2K, but could you set up a group in the win2k domain which has ICS turned off, or restricts their access to the ICS host (if it's not the win2kserver, that is )? Then put this person in this group for rights?

Tell me if I'm barking up the wrong tree; as I said, I don't know much about domains, only what I've fiddled with on my home LAN in winNTserver.

Cheers
Mick
  Reply With Quote
Old September 7th, 2002, 07:05 PM     #6 (permalink)
addicted
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 6,103
I can't think of a way to do this at the server with ICS. The best I can think of with Mickwish's idea is too set u pa special OU for this computer and create a Group Policy that makes him use a proxy address that does't exist. This would only work for IE + OE though.

If this person had a static IP address then you could block his IP address with ZA (or some 3rd party software).

If it is dynamically assigned by ICS then you need a 3rd party software that would filter on MAC address. I don't know what that would be though.


A different approach would be getting rid of ICS and use W2K Server's NAT or use a proxy application. Most proxies allow authentication methods before granting access.
DVNT1 is offline   Reply With Quote
Old September 7th, 2002, 10:41 PM     #7 (permalink)
Ultimate Member
 
skuz's Avatar
 
Join Date: Oct 2001
Location: Quebec, Canada
Posts: 1,784
Well I'm not on a domain and he does not log on to Windows, so a GPO can't be used.

I'll try to find a solution from your answers and the ZA suggestion is a good idea.
skuz is offline   Reply With Quote
Old September 8th, 2002, 08:36 AM     #8 (permalink)
Ultimate Member
 
Cyclone2's Avatar
 
Join Date: Oct 2001
Location: Ont. Canada
Posts: 1,842
I believe ZA will work if you have static or dynamic ips, it will just require a different way of blocking that comp.
Will require a bit of playing around
Cyclone2 is offline   Reply With Quote
Old September 8th, 2002, 09:01 AM     #9 (permalink)
addicted
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 6,103
yes, it can block the IP address regardless of how that IP address was given. Its just with a dynamic IP address you will eventually block the wrong computer when the IP addresses change.
DVNT1 is offline   Reply With Quote
Old September 9th, 2002, 02:34 AM     #10 (permalink)
Senior Member
 
Join Date: Oct 2001
Posts: 881
Send a message via AIM to zskillz
couldn't you set up ICS to only allow use to members of a group... that way if he doesn't logon, then he can't use it?

-Z
zskillz is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (1596)
CBO: Obama's health care plan cuts .. (103)
USB not recognised..... (16)
What Happens If You Have Health Ins.. (7)
would this build be enough for WOW? (14)
Recent Problem (15)
Need some suggestions on building a.. (30)
[ F@H Chat] 03/07/10 New Month New.. (89)
Can't Rename Files (12)
Motherboard the culprit? (7)
Suggestions? (6)
Windows XP Pro Error log (9)
Hard drive full = slower computer? .. (6)
Want a new power supply for my Dell.. (35)
Recent Discussions
First time builder (2)
Can't Rename Files (12)
Need some suggestions on building a g.. (30)
YOUR BEST TRICK OR TIP FOR YOUR COMPU.. (22)
169 ip address question (4)
Help! Cisco Switch port (interface) f.. (1)
Motherboard the culprit? (7)
About to install a new heatsink and I.. (1)
SSH Tunnel Or OpenVPN? (0)
burner not burning. (4)
Windows XP Pro Error log (9)
Sim Societies won't launch (0)
[ F@H Chat] 03/07/10 New Month New T.. (89)
HTML (2)
Hard drive full = slower computer? Is.. (6)
Reading Raw data off an SD (MMC) card (8)
Recent Problem (15)
USB not recognised..... (16)
Can i upgrade my gateway nv5448u grap.. (1)
Drive 0 not found: Serial ATA, Sata-0 (9)
i need to find my DNS server IP addre.. (21)
HP Pavillion Laptop ze4220 won't turn.. (15)
Lexmark Printer Prestige pro805 (0)
E:\Pictures is not accessible. the d.. (4)
Replacement hard drive for Dell 600M (18)


All times are GMT -4. The time now is 05:21 AM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28