Connect. Communicate. Collaborate. Securely.

Home » Kerio User Forums » Kerio Control » Rules and Policies
  •  
atomala

Messages: 14

Karma: 0
Send a private message to this user
Have intalled Kerio Winroute Firewall latest version. How can I configure it so I could give full access to internet to a group of IP, and limited access (specifically sites) to other group of IP`s for a special schedule of time. I configured the IP groups, the schedules, configured the transparent proxy. The problem arises that policies established don´t work...any ideas or help?


Augusto Tomala
ENER-IT
  •  
feite

Messages: 523
Karma: 0
Send a private message to this user
create a traffic rule that allows http-proxy access from lan to proxy. create a second traffic rule that allows http/https access from firewall (= proxy) to internet.

create an address group for the limited http users and place their ip addresses in that group.

create an url group for the urls the limited users are allowed to access.

create a http policy for the limited users. select the url group at 'is in url group' (first tab). set action to allow. on the advanced tab select the address group at 'valid for ip address group'. this rule allows internet access for the limited ip addresses to the selected urls.
create a second http policy below the first. select 'url begins with' and enter a '*' (first tab). set action to deny. on the advanced tab select the address group at 'valid for ip address group'. this rule blocks access to the internet for the limited ip addresses.
create a third http policy below the second. select 'url begins with' and enter a '*' (first tab). set action to allow. this rule allows access to the internet for all the other ip addresses.
Previous Topic: Lost Email when sent
Next Topic: how to backup an restore the setting?
Goto Forum:
  


Disclaimer:
Kerio discussion forums are intended for open communication between forum members and may contain information and material posted by members which may be useful in learning about Kerio products. The discussion forums are not intended to provide technical support for any specific product. Any information implied or expressed in the discussion forums is that of the posting member. Kerio is in no way responsible for the information posted in the forums, or its accuracy. Kerio employees may participate in the discussions, but their postings do not represent an offical position of the company on any issues raised or discussed. Kerio reserves the right to monitor and maintain the forums to promote free and accurate exchange of information.

Current Time: Tue Nov 21 12:51:09 CET 2017

Total time taken to generate the page: 0.00332 seconds
.:: Contact :: Home ::.
Powered by: FUDforum 3.0.4.