HT5413 Help filtering internet access

+PAX
Greetings all, and a Merry Christmas!
We're a small monastery. And due to this, we need to implement some Internet filtering. Unfortunately, it's not the basic kind of filtering. Frankly, I'm not sure that all of what we're looking to do can be done. But I'm at a loss about where I can look for this information.
At the moment, we've got a basic network, that you'd find a family home: DSL modem-router, a bunch of Ethernet hubs, and a whole bunch of cables.
The computers are mainly running Fedora Linux. There are 3 windows statioins, and 2 OS X stations.
The perfect solution is to be able to have 1 network, where there are 2 or 3 rooms where the Internet is accessible. And, those who have laptops, that they can bring their laptop to these rooms, and have Internet access, but NOT have access while connected to the network in other places. (Complicated, I know).
If that's not possible, ok. (Frankly, I don't think it is, but am very open to suggestions).
What really do need is to be able to allow an Internet connection, restrict bascially all web-surfing, while allowing e-mail, skype, and updates. The updates are my biggest problem. We already have a rule established on the modem-router that blocks surfing activity at night, but still allows e-mail and skype. Yet, this rule also blocks the apple AppStore updates.
So, I'm wondering if we get OSX server, would this help the situation? Where can I get more info about OSX server's filtering capabilities?
If we can't establish all the blocking that we need, then it'd be great if we could have some type of report of each person's activity.
Thanks for the help!

IMO, OS X Server won't be a good solution as a network filter.  It might be useful here, but it very likely won't be your most appropriate choice as a network-gateway-router system.
FWIW, I'd suggest pursuing this in a Fedora-focused networking forum, in general.  This given that's your most common platform.
Assuming wired networks, you can divide up the access via managed switches and a VLAN, or via physical network segmentation.  WiFi is somewhat harder to segment, short of having a guest network and a private network; you'd need access points (APs) with two networks configured, one of which allows a little more access, and the other that's presumably restricted to the local IP address space.
There are gateway routers around which allow several different segments to be maintained, but they're generally starting in the ~US$250 range and upwards, and usually expect a little more knowledge of IP networking and related topics than the residential routers that are in common use.
Here is Apple's network port list.
As for the updates, OS X Server can cache those, as can the Reposado tool on a Fedora system.
A common solution involves a web proxy filter, where all connections must pass through that device.  The connections used for the OS X Server or Reposado server itself to download updates would need to be programmed to allow access, but the other local OS X clients could be aimed at the local server.  In your case, your filter can block all outbound connections to TCP 80 and TCP 443 entirely, save for the specified servers loading updates from their respective upstream sources.
Email is fairly easy, as you'll probably want to block outbound TCP 25, but allow POP via SSL and IMAP via SSL and allow the submission ports (TCP 486 and TCP 587).
Now for the somewhat bad news: these general approaches can often be bypassed using VPNs and tunnels, so somebody that's knowledgeable can generally get around simple-minded network filters.  Which means you can end up blocking more than a little outbound traffic; more than TCP 80 and TCP 443. 
Now for somewhat more bad news: Skype uses TCP 80 and TCP 443 (or requires a whole lot of open ports), and specifically to work around filters and blocks and firewalls and related "defenses".  Whether you can get that to work by excepting the supernodes, I don't know.
I'd probably sort out what you do and do not want to allow access to as a more general problem, as getting an update server into a DMZ with exceptions enabled is a comparatively small problem — once you achieve the sorts of network blockages you're seeking.  None of this stuff is particularly specific to OS X or OS X Server, either.  
This configuration will probably involve installing a network gateway with internal filtering capabilities and a network nanny implementation, as well as some work on the internal network configuration.  That may well be possible with Fedora, DD-WRT, Tomato or some other similar open source (it's likely best to ask for discussions and tradeoffs of those options elsewhere), and can be implemented with a commercial offering.  Your needs here are probably even a little simpler in some ways, as you want and need just a few web connections.

Similar Messages

  • Filtering Internet access?

    +PAX
    Greetings all, and a Merry Christmas!
    We're a small monastery. And due to this, we need to implement some Internet filtering. Unfortunately, it's not the basic kind of filtering. Frankly, I'm not sure that all of what we're looking to do can be done. But I'm at a loss about where I can look for this information.
    At the moment, we've got a basic network, that you'd find a family home: DSL modem-router, a bunch of Ethernet hubs, and a whole bunch of cables.
    The computers are mainly running Fedora Linux. There are 3 windows statioins, and 2 OS X stations.
    The perfect solution is to be able to have 1 network, where there are 2 or 3 rooms where the Internet is accessible. And, those who have laptops, that they can bring their laptop to these rooms, and have Internet access, but NOT have access while connected to the network in other places. (Complicated, I know).
    If that's not possible, ok. (Frankly, I don't think it is, but am very open to suggestions).
    What really do need is to be able to allow an Internet connection, restrict bascially all web-surfing, while allowing e-mail, skype, and updates. The updates are my biggest problem. We already have a rule established on the modem-router that blocks surfing activity at night, but still allows e-mail and skype. Yet, this rule also blocks the apple AppStore updates.
    So, I'm wondering if we get OSX server, would this help the situation? Where can I get more info about OSX server's filtering capabilities?
    If we can't establish all the blocking that we need, then it'd be great if we could have some type of report of each person's activity.
    Thanks for the help!

    The original question AND ANSWER, is available here:
    https://discussions.apple.com/message/24257220#24257220

  • Safari and firefox stop working after a few minutes of browsing, regardless of what site I'm on. I have to restart my computer to get internet access again but it only works for a few more minutes, then I have to restart again. Please help!

    Safari and firefox stop working after a few minutes of browsing, regardless of what site I'm on. I have to restart my computer to get internet access again but it only works for a few more minutes, then I have to restart again. I don't get a spinning ball, it just stops working at whatever page it's on. I can close the program just fine but when I re-open it, either safari or firefox, it freezes trying to load the hompage. This started a few days ago after trying to stream a movie on my computer. I'm on a Mac Air OS X Version 10.6.8 and have downloaded all updates. When I go into finder, it says I have over 80 gigs available. Is there some other memory cache that I need to check? Thanks so much for your help.

    ejwoodall wrote:
    It's not a router problem as I explained in my post. If it was a router problem then I wouldn't have the problem everywhere I go. It is an issue with the software.
    Then I guess the millions of people running 10.5.7 with no issues are just hallucinating that their machines are working fine?
    I'm not trying to belittle your issues; you're certainly having them and I know first hand how annoying an intermittent AirPort issue can be. (In fact, mine was due to an AirPort driver bug that no one else seemed to suffer from.)
    The single best diagnostic you could do is take your system running 10.5.7 to an Apple Store, and try using their in-store network.
    If your machine performs flawlessly, it may be a router issue.
    If your machine has connectivity issues there, it may be a hardware problem with your machine.
    There have been numerous people in multiple threads over the years who swore that an update was buggy because things used to work, but returned later to sheepishly admit that they took their machine in, a problem was found and fixed, and now their Mac works flawlessly with the newer software.
    But simply reinstalling 10.5.5 in no way means the explanation of how firmware bugs may be at play here is incorrect.
    In the context of that explanation, all you've done is possibly reinstall software that asks to add "2 + 3."

  • New WRT320N - slow internet access help!

    Hi, we'e just installed a new WRT320N. We have broadband access via Virgin Broadband and have a fairly new modem. When we access the internet via the router it is really slow. This is the case whether the connection is wired (our PC doesn't have wireless, so the connection is wired - ie cable between router and modem and then cable between router and PC) or wireless (ie PC with wireless n card). If I unplug both and reboot, connection is initially fast and then slows down again.
    If I connect the computer directly to the modem, the speed of internet access is fine. So there is nothing wrong with broadband generally, it is definitely something to do with the Linksys router and possibly the way it is communicating with the modem.
    The one thing I've noticed is that when connected directly via modem without the router, speed is 100 mbps whereas when connected with Linksys router, speed is 1.0 Gbps.
    Help! Thinking of giving up and returning the Linksys router and going with the one Virgin recommend (Netgear) but we'd rather not.
    Virgin tech guys said we might need Linksys firmware update?
    Anyone got any ideas? We're not v techie here and clueless .... Thanks v much!

    100Mbps is the maximum supported on a Virgin modem, whereas your "gigabit" router is capable of outputting at 1Gbps or 1000Mbps. This is normal and has no bearing on your issue.
    Go into the router config page at 192.168.1.1, change the MTU size to 1350, reboot both modem and router and see if that makes any difference.
    Also check what version of firmware you have, it will tell you in the config (top right hand corner usually)
    The latest available here is: Ver.1.0.03 build 10
    http://www.linksysbycisco.com/UK/en/support/WRT320N/download
    Message Edited by Matt Hall on 02-07-2010 07:13 PM

  • Can anybody help me to access Internet with my existing network

    Dear All Recently I purchased new WRT 54G wireless router. Also I have tied up with new ISP to give wireless internet access to some of the my Higher authority employees only. My office network setup is as shown below Local Ip range : 172.18.0.0 to 172.18.2.254 subnet mask : 255.255.0.0 Default gateway : 172.18.0.50 Wireless Router configured as : 1) configured all ISP settings 2) configured LAN site setting( But I had to setup lan as 192.160.1.X i.e the required by ISP ). 3) connected ISP lan port of WRT54G to cable coming from ISP Modem 4) Connected Local port( any one of 4 ports) to my existing switch(existing LAN----172.18.x.x network) Now suppose I configure user laptop to access new ISP internet through wireless.I have done following setting Wireless LAN setting : Ip address : 192.168.1.2( I can give any IP of network 192.168.1.x) subnet mask:255.255.255.0 Default gateway :192.168.1.1 DNS : Automatic I can access the new ISP internet without any problem with WRT54g router. But the problem is while accessing the new ISP internet( Using 192.168.1.x/255.255.255.0/192.168.1.1 network),Also I want to access my existing network( 172.18.0.0/255.255.0.0/172.18.0.50). Since I am very weak in routing the network, can anybody help me out to do routing setting in linksys WRT54g router so as to access my New ISP internet using existing network( 172.18.0.0/255.255.0.0/172.18.0.50). Please help me anybody

    O.K. Still the crucial question remains whether you want the separation of the ISPs enforced or not, i.e. do you actively want to prevent someone to switch to the other ISP simply by reconfiguring some settings on the computer or not?
    If you don't want to enforce the policy and it is enough to just use different IP settings on different computers then this would probably be the easiest solution.
    If you can, install a DHCP server (e.g. on a Linux box) inside your network which does the DHCP address assignments. That way you can dynamically assign the proper addresses to the computers.
    You can then assign the WRT an LAN IP address inside the 172.18 subnet. The DHCP server assigns anyone addresses inside your 172.18 subnet. However, you configure different gateway and dns server addresses depending on the computer. You configure the MAC addresses of those 'preferred' laptops the gateway address of the WRT and the public DNS servers of the new ISP. All other computers you assign the old gateway address of the old router and the DNS server addresses of the first ISP.
    If you don't want to install your own DHCP server you can assign either pool static IP addresses, i.e. assign all preferred laptops static IP address including the gateway address of WRT and use DHCP only for the normal computers or vice versa.
    What won't work reliably is to run two DHCP servers on both routers and connect the LAN of both together. You'll end up with computers picking up the wrong IP address from the wrong DHCP server.
    Again, this separation only happens due to the different configuration of the computers. If anyone can freely reconfigure the computer he has it is easily possible to change the gateway address and thus swap the ISP. But as long as people comply with the rules it works.
    If you want to enforce the separation you will have to install another router between the two gateway router. This third router passes traffic from the WRT subnet for the 172.18 subnet and accepts the return traffic. In the opposite direction the router does not forward traffic. You should even be able to use a standard NAT gateway router and hook up the internet port to the 172.18 subnet and the LAN port to the WRT. You then configure a static route on the WRT to forward packets for 172.18 subnet to the third router. If the third router does not NAT then you have to configure another route on the first router to forward traffic for WRT subnet (192.168.1.*) to the third router as well.

  • No internet access of MacBookPro and D-Link DI-624, please help.

    Hello there,
    My week 13 build MBP cannot connect to internet, please advice me what I can do (in both MBP settings and router settings) to make internet connection stays ON.
    I have been struggling with this problem for weeks. I am a new Mac user, and I thought I messed up my system settings in the beginning, therefore I even go to extreme to redo the recovery back to factory condition. Before the recovery, internet works, but not so often. Right after the recovery process, the internet still don't work.
    I have tried like some other threads says to add a $ sign before the WEP P/W, no help. AS A MATTER OF FACT, I have purposely enter an invalid p/w for the WEP, and Airport still accepts it, or adding the $ sign before a valid p/w. Both situations the Airport shows I am connected to my home network........that really beats me.
    After a few more trys with a valid p/w, last night it finally works. I can swear nothing out of ordinary did I do this time, just happens. But after a restart of computer, the internet access is gone aagain.
    Before the recovery, the system is 10.4.6, with the CD that comes with my computer, the recovery system is 10.4.5. I have seen from other threads that some users after upgrading to 10.4.6, their internet drops, IS THAT TRUE? But the thing is, after my recovery with 10.4.5, my internet doesn't work right off the bet.
    Any DI-624 and MBP users out there who have made theirs units work, please help and respond.......thanks in advance.

    Thanks for replying and the advice you offer.
    The connection still won't work.
    What I did is first connect a cable from my MBP to the router, then using a PC to web configure the router settings. (BTW, my firmware is the latest one 2.70)
    Disable : Super G Mode, Extended Range Mode, 802.11g Only Mode and all Security.
    Enable: SSID Broadcast
    Then turn on the MBP, go to System Preferences – Network:
    Location: Automatic
    Show: Built-in Ethernet
    Under tab TCP/IP:
    Configure IPv4: Using DHCP
    IP Address: 192.168.0.xxx
    Subnet Mask: 255.255.255.x
    Router: 192.168.0.x
    DHCP Client ID: blank (don’t know what that is?)
    DNS Servers: blank (don’t know what that is?)
    Search Domains: blank
    IPv6 Address: xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx
    Click Renew DHCP Lease, same values shown.
    Turn web browser on, not connected.
    Did I do or enter anything wrong? I have not re-enter the wireless security yet since the wired connection is not working.
    But I did notice something in the router setup for security:
    Security options are Disable, WEP, WPA, WPA2 (my choice), and WPA2-Auto
    Then anytime you select either WPA, WPA2, or WPA2-Auto, they will show the following choices:
    Cipher Type [(TKIP, by default, and my choice), or (AES)]
    PSK/EAP [ (PSK, by default and my choice), or (EAP)]
    Then enter and reconfirming “passphrase”.
    Please indicate if this is something you have. Thanks for the help again.

  • RV042 Need help (2) AT&T DSLs setup. No Internet Access

    Small Business setup of a dozen computers.
    I am trying to get more bandwidth so have added a second DSL.
    I am setting up new RV042 with two AT&T DSLs.
    I have only (1) dsl modem (192.168.1.253) connected to RV042 to test setup. Have configured RV042 with user name and password for dsl.
    dsl modem IP is 192.168.1.253  (second modem already has default 192.168.1.254)
    RV042 IP is 192.168.1.1
    Compter OS is Windows XP
    Computer IP is set with Static IP 192.168.0.147
    Computer Default Gateway is set  for 192.168.1.1
    When I try to access the Internet from computer I get sent to ATT with problem and following the on screen suggestions, finally error says I have no Internet Connection.
    However I can ping google.com and yahoo.com from command window with this setup.
    If I remove RV042 and connect computer to dsl modem and reset default Gateway to ip of modem (192.168.1.253) I get Internet Access so It is working.
    Why then do I not get Internet access thru RV042?
    I turned off firewall on computer.
    Set to Load Balance instead of Backup
    Set Primary WAN to #1 where I connect to dsl modem.
    Turned OFF dhcp on RV042 which is being handled by original modem.
    I have not yet talked to ATT support about the RV042 to see if they can offer help.
    Any help will be appreciated.
    John

    John
    Reading over your post its best to give Cisco Small Business Support Center a call @ 1-866-606-1866 and open a support case. We need to get a better understanding on how everything thing is connected and configured. There is a lot of conflicting information and could case possible topology integrity if not corrected.
    Jasbryan

  • My internet access keeps dropping!!! Help

    My ISP is comcast and i am running a lynksys modem and WRT54G router.  Desktop on a cable to the router and 2 laptops and another desktop hooked up wirelessly.  Things will run beautifully for awhile and then internet access will just drop - for both the desktop and all wireless nodes.  Internet light on the router is still flashing like its ok, but its down.  I have to shut down router/modem and dekstop to re-establish  internet.  Also, when internet goes down, even though internet light on router is flashing i cant get to it with the 192.168.1.1 address.  Ideas?  Im losing my mind troubleshooting this!  Thanks.
    Husker

    try to connect your computer directly to the modem....
    if its still giving you the same problem verify yOur connection from your internet service provider...
    if its giving a goOd connection the firmware on your router might need to be updated...
    hOpe this helps...  

  • IPhone 5S joins wifi but no internet access - help!

    Forgive the length of this, I've browsed past threads about this problem and googled everything I could, but I can't fix the issue.
    iPhone 5S, iOS 7.0.4
    I have a MacBook Pro, a Time Capsule, several airport expresses, an iPad and AppleTV in my house... all are working fine (internet access unaffected).
    The iPhone worked perfectly until two days ago... the internet access just disappeared for no apparent reason.  Wi-fi strength is always strong; never a problem joining.
    These are the things I've found on the interwebz and tried:
    Rebooting my Xfinity router (multiple times)
    Rebooting the iPhone (multiple times)
    Turning wi-fi off, then on again (a zillion times)
    "Forgetting" my wi-fi network, then rejoining
    Changing DNS to 4.2.2.4 and back again
    Resetting network settings on iPhone
    Renewing lease in wi-fi settings
    Checking/reviewing my Xfinity router settings and all connected devices
    What am I missing?
    Aside from returning the phone and getting a replacement, is there anything else I can do?
    Any help/suggestions will be appreciated!

    thanks for the suggestion.  i did change the broadcast channel and this may hopefully help with an unrelated problem with occassional interference, but sadly it did not help with the iPhone issue.
    everything still works fine, except the internet connection on the iPhone.  sad face.... anyone else?

  • My Ipad connects with my hotel wifi, but does not indicate that it is a secure wifi, even though it requires a password to access - no lock symbol, hence no password request, hence no internet access - help.

    My IPad connects with my hotel wifi, but does not indicate that it is a secure wifi, even though it requires a password to access - no lock symbol appears against the wifi network, hence no password request, hence no internet access - help. My collegue who also has an Ipad can access the same wifi with ease, so it must be something to do with the settings on my machine, although checking the two machines, there appears to be no difference in the settings.

    My experience with hotel wifi is that it's an open, and unsecured, connection, but unless you agree to their terms on a launch page, you can't go any further or connect. Sometimes I need to force safari to come up and even make it go to a page, to trigger the auto load of the 'agree to our terms' page.
    Unless your machine is work provided so maybe could be blocked from unsecured net access?

  • Airport Extreme - Remote is not passing internet access - help please

    I have the following:
    Cable modem - > WAN of Airport Extreme. - works perfectly - wireless clients in range get internet access and the network works.
    Second Airpot Extreme set to relay this network. It connects, gets a "green" light - seems to be set up properly, but wireless clients in that area cannot get internet. Why is it not passing internet.
    Can anyone explain step by step how to do this or post a link to an apple doc?
    Thank you,
    Miklos.

    Hi, actually this is still not working.
    I got the second base station configured so that when it started up, it was working properly as a "remote" station, and I was getting internet fine through an ibook there (which is normally too far away from the main station to get any signal).
    However, today, although the second "remote" station still has a green light and is connected to the network it is not getting an IP address from the main base station - and so I can't get any internet through that 2nd base station anymore.
    Why was it working yesterday and not today when I've changed nothing?
    Any help much appreciatd.
    Miklos.

  • I turned off Internet access, using airport timed access control.  Now, I can't turn it back on.  The base station can't be found.  Please help.

    I turned off Internet access, using airport timed access control.  Now, I can't turn it back on.  The base station can't be found.  Please help.

    Can you take a look at this one and offer your opinion please?
    https://discussions.apple.com/message/21889032#21889032

  • PSE10 - How to get the online help on PCs with no Internet Access ?

    Hello,
    Our company has bought several licences of Photoshop Elements 10 and would like to package the installation in order to be able to install it with SCCM (formelly called SMS) on PCs.
    The issue we've got is that the PCs in our company don't have Internet access, so Users can't, after the installation, download the help online... and since there is no offline help included, that means they don't have any help at all.
    Can you let us know where the help in question is copied when it is downloaded, so that our packaging team will be able to download those files from a PC with Internet Access and then add them in their package so that our Users will be able to read the Help (F1) even if they don't have Internet access ?
    Thanks a lot for your reply

    yes you can do that by changing settings in Adobe Help Manager
    Open Adobe Help.exe from the location :  c:\program files (x86)\Adobe\Adobe Help
    Then in the download prefrences section , you can select the products you wish to have offline help
    In the updater section select manually
    In the local content section : select the product and click UPDATE
    when the offline help is downloaded, then in the general section, select Yes (this will make the local help default)
    Now if you can go offline, and press F1 within the program , it will open the local help
    Hope it helps !!

  • My MacBook Air says it in connected to my wifi, but my wifi signal has a "!" sign on it. My computer will not allow internet access, help?

    My MacBook Air says it in connected to my wifi, but my wifi signal has a "!" sign on it. My computer will not allow internet access, help?

    When you see an exclamation point in the Wi-Fi menu, from the menu bar, select
     ▹ System Preferences... ▹ Network
    Click the Assist me button and select Assistant. Follow the prompts. You may get a warning that Wi-Fi is not available, that you're too far from the base station, or that you're using the wrong password.
    Assuming that you've ruled out those possibilities, restart the computer and try again. If there's no change, click the lock icon in the lower left corner of the preference pane and authenticate, if necessary. From the Location menu at the top of the window, select Edit Locations. A sheet will drop down. Click the plus-sign button to create a new location. Give it any name you want. In the new location, set up the Wi-Fi service with the same settings you used before. Click  Applyand test.
    If there's still no connection, and if you have control of the router, compare its settings to Apple's recommendations. Some third-party routers may be incompatible in 802.11b/g/n radio mode. Try setting the mode to 802.11n only.

  • Need help turning off autoupdate without Internet access for Reader 9

    Does anyone know how to disable the auto-update for Adobe Reader 9.0?
    The only article I have seen explains how to disable the update for 7.0 or 8.0 (both change a registry key bUpdater to 0, which does not exist for 9.0).
    Anyone have an idea?
    Thanks!

    The only way I know to disable it is to go to Help>Check for updates.... Let it do it's thing then click the "preferences" button and deselect "Automatically check for Adobe updates."
    I'm not positive what happens if you try this without internet access...

Maybe you are looking for

  • FTP to ABAP Proxy Scenario - getting error CO_TXT_CHANNEL_PASSWORD_ERROR

    We have transported PI and EP data from development server to respective production, every thing is running fine except the abap proxy scenarios i.e. PI reads file from ftp location and calls the abap proxy but we are getting following errors: <?xml

  • Problems opening PDF in Adobe Reader

    When I try to open a PDF using Adobe Reader the Adobe Reader page opens but not my PDF. The computer freezes for a few seconds and then the Sdobe Reader page shuts down. I have tried uninstalling and reinstalling with no sucess. If it makes any diffe

  • Download Photoshop Elements 8 for Mac?

    Hello. Can I download Photoshop Elements 8 for Mac? I need to activate a new mac without a CD drive and have de-activated old one?

  • Default new app settings

    It seems, since I upgraded XCode to v. 3.2.6, that every app I create wants to compile for the iPad and run in the iPad simulator. When I change the project settings, they seem to go back to iPad on a pretty regular basis. Where can I set this to def

  • Color artifacts in DNG files

    Hi, I've got a major issue with Adobe PS Lightroom DNG import on my Mac from my Canon EOS 5D Mark III. Any image converted to DNG file format is showing heavy color artifacts around edges, whereas the color of the object in focus is abruptly replaced