public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
From: "Matt Causey" <matt.causey@gmail.com>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] Restricting Firefox website access
Date: Sat, 10 Jan 2009 19:35:56 +0000	[thread overview]
Message-ID: <ac71f2bb0901101135u279e34cdt5765375f1e47a6f7@mail.gmail.com> (raw)
In-Reply-To: <49bf44f10901100950i7dbf2fcp93a6c06882fd1c1f@mail.gmail.com>

>>>
>>
>> I think you would do well to setup a squid proxy and block outbound
>> traffic for the affected machines.  We've had great success with squid
>> in our environment.  This gives you a tremendous amount of flexibility
>> on your access control, and it means you don't have to be concerned
>> about which transport methods are used when updating/installing.
>> Added bonus is that the squid caches your Gentoo download objects.
>
> Is that tough to set up?  I would think an iptables solution would be
> easier, but maybe that won't work out.
>

Well, you'll end up using iptables anyway right?  If you really want
to -force- folks to get out through a proxy, that is.  Since you
mention that the router is a gentoo box, should be an easy one.

Tough to setup Squid? Naw.  Of course, it's like most things, we don't
know much about your network or the scope of your requirements.  For
our use case, we needed the following:

-forced access through the proxy
-website URL blacklisting and custom redirection based on massive regex lists
--Automated notification on certain 'violations'
-user account login to the proxy before internet access
-username tied to all proxy logs
-'manager' access to log data via nifty graphs on a web server

So, ours took some time.  :)

Ya, I know these folks were uuber paranoid, and wanted the ability to
nab folks for what they felt like was inappropriate internet usage...
Anyway your situation sounds much simpler.  So simple in fact that
just a few tweaks to the default squid.conf can provide you with a
functional config.

There are heaps of doco out there on configuring Squid, so you should
have a look and see what you think.  You can easily get a little test
proxy going on a desktop or laptop to try it out.  :-)

Hope this helps!

--
Matt



  reply	other threads:[~2009-01-10 19:35 UTC|newest]

Thread overview: 33+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-01-07 21:44 [gentoo-user] Restricting Firefox website access Grant
2009-01-07 21:54 ` Paul Hartman
2009-01-08 20:57   ` Kyle Bader
2009-01-09 18:40     ` Grant
2009-01-09 19:05       ` Alan McKinnon
2009-01-09 19:32         ` Grant
2009-01-09 20:58           ` Kyle Bader
2009-01-09 21:07             ` Nick Cunningham
2009-01-09 21:23           ` Alan McKinnon
2009-01-10 10:14           ` Peter Humphrey
2009-01-10 14:35           ` Matt Causey
2009-01-10 17:50             ` Grant
2009-01-10 19:35               ` Matt Causey [this message]
2009-01-10  5:18       ` Mike Kazantsev
2009-01-10 17:48         ` Grant
2009-01-11  2:05           ` Mike Kazantsev
2009-01-11  2:27             ` Grant
2009-01-13 19:33             ` Mick
2009-01-14  1:52               ` Mike Kazantsev
2009-01-17  5:34             ` Grant
2009-01-17  6:30               ` Mike Kazantsev
2009-01-17  9:50                 ` Peter Humphrey
2009-01-17  8:47               ` Alan McKinnon
2009-01-17 18:12                 ` Grant
2009-01-17 18:21                   ` Alan McKinnon
2009-01-17 18:53                     ` Matt Harrison
2009-01-17 18:24                   ` Grant
2009-01-17 15:43               ` Stroller
2009-01-17 16:32                 ` [gentoo-user] " Harry Putnam
2009-01-17 17:40                   ` Grant
2009-01-17 19:02                     ` Harry Putnam
2009-01-17 17:32                 ` [gentoo-user] " Grant
2009-01-23 11:04                 ` Matt Causey

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ac71f2bb0901101135u279e34cdt5765375f1e47a6f7@mail.gmail.com \
    --to=matt.causey@gmail.com \
    --cc=gentoo-user@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox