LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-16-2005, 03:34 AM   #1
matux
Member
 
Registered: May 2004
Posts: 51

Rep: Reputation: 15
Outbound URL Filtering


I am using Mandriva 10.1 and have installed shorewall version 2.0.8. I have blocked all access to the internet but want to allow users access to just a few websites. I was wondering how i could do this and is shorewall the best option?

Thanks for any help.
 
Old 12-16-2005, 07:57 AM   #2
matux
Member
 
Registered: May 2004
Posts: 51

Original Poster
Rep: Reputation: 15
Forgot to add my shorewall files just in case its any help.
Thanks



SHOREWALL.CONF
LOGFILE=/var/log/messages
LOGFORMAT="Shorewall:%s:%s:"
LOGRATE=
LOGBURST=
BLACKLIST_LOGLEVEL=
LOGNEWNOTSYN=info
MACLIST_LOG_LEVEL=info
TCP_FLAGS_LOG_LEVEL=info
RFC1918_LOG_LEVEL=info
SMURF_LOG_LEVEL=info
BOGON_LOG_LEVEL=info
PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/bin:/usr/local/sbin
SHOREWALL_SHELL=/bin/sh
SUBSYSLOCK=/var/lock/subsys/shorewall
STATEDIR=/var/lib/shorewall
MODULESDIR=
CONFIG_PATH=/etc/shorewall:/usr/share/shorewall
RESTOREFILE=
FW=fw
IP_FORWARDING=On
ADD_IP_ALIASES=Yes
ADD_SNAT_ALIASES=No
TC_ENABLED=No
CLEAR_TC=Yes
MARK_IN_FORWARD_CHAIN=No
CLAMPMSS=No
ROUTE_FILTER=No
DETECT_DNAT_IPADDRS=No
MUTEX_TIMEOUT=60
NEWNOTSYN=Yes
ADMINISABSENTMINDED=Yes
BLACKLISTNEWONLY=Yes
MODULE_SUFFIX=
DISABLE_IPV6=Yes
BRIDGING=No
DYNAMIC_ZONES=No
PKTTYPE=Yes
BLACKLIST_DISPOSITION=DROP
MACLIST_DISPOSITION=REJECT
TCP_FLAGS_DISPOSITION=DROP
#LAST LINE -- DO NOT REMOVE

INTERFACES
no interfaces

ZONES
net Net Internet
loc Local Local networks
dmz DMZ Demilitarized zone

POLICY
loc net ACCEPT
net all DROP info
all all REJECT info

RULES
ACCEPT net loc:216.239.39.99 tcp http[/b]
 
Old 12-17-2005, 03:21 AM   #3
DaveG
Member
 
Registered: Nov 2001
Location: London, UK
Distribution: Fedora
Posts: 161

Rep: Reputation: 43
Have you considered using web proxy software? In my small network, all direct internet access is denied by the router - everything has to go via the privacy-enhanced proxy running on a server. The URLs get logged, URLs are restricted and the HTML is filtered to remove most of the normal dross/abuses such as pop-ups, cookie tracking, advertising, etc.

With the client proxy configuration set up properly, all local content is accessed directly while all internet access is via the proxy.

See http://www.privoxy.org/
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Inbound web URL filtering anoop_sweet Linux - Security 4 12-11-2005 11:45 PM
URL Filtering in NAT+BIND9 TheAce Linux - Networking 8 11-08-2005 01:40 AM
set URL filtering in mozilla Trio3b Linux - Security 2 04-15-2005 06:19 AM
url filtering using Squid RajaRC Red Hat 1 11-07-2003 07:21 AM
Web filtering: URL filt or rate content..or? Linux Learning Linux - Security 2 10-01-2003 07:46 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:02 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration