Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Block Http access in 2004

Status
Not open for further replies.

brea

IS-IT--Management
Nov 15, 2002
86
US
So I'm a bit new to ISA. Thanks for the help...

I have inherited an existing installation and there is a small problem.

There is a specific group of users that we want to permit http to a small set of sites and then deny all other sites. There are currently three rules that are in use here. they are listed in the order they appear.

1. Permit the specific group of users to 5 sites for HTTP(s), and FTP.
2. Deny the specific group of users to all HTTP(s), and FTP
3. Permit all domain users for all HTTP(s), and FTP

Now it seems that when the permit rule comes into play the log indicates that it was accepted. When a site is accessed that the deny rule should block the log states that the 3rd rule permits the traffic to go out.

Any idea why this is? The rules are processed until a rule is matched to the traffic correct?
 
YOu should technically have the DENY rule last, on any firewall DENY's should always be the last rule...i'm not sure if what you're trying to do is a little complex for non-content filtering software....

Let us know if this helps?

Thanks,
Mike FIrth

Michael Firth
Network Infrastructure Officer

~If it's not broke, break it and LEARN~
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top