Can I restrict a single computer to a single website?
All Replies
-
Currently there is no On site reputation filter allow list only
https://community.zyxel.com/en/discussion/31412/on-site-reputation-filter-allow-list-only
or a way to do Web Content Filter allow list only from what I can tell as it meant to be a block Filter on Content to then allow exceptions.Some thing I have been doing that you can do if you make this one client by fixed IP or DHCP IP MAC binding is WILDCARD FQDN depending on the firewall model your using Currently you can do like *grc.com or grc.com and *.grc.com and make a group list of these WILDCARD FQDN so that you can make a policy control rule to block from LAN to WAN source IP of client then a from LAN to WAN source IP allow rule for DNS NTP and anything else then a from LAN to WAN source IP allow rule for HTTPS and the destination WILDCARD FQDN group.
Now when the client does DNS in the clear (not encrypted) the USG will see the DNS and add IP's to the WILDCARD FQDN to then allow under the rule
Note that some sites have 3rd party links and if you don't allow them the browsing can be slow
0 -
delete
0 -
delete
0 -
Hi @bwoolley ,
As requested, the following example demonstrates how to restrict a single computer to access only one specific website, while allowing all other computers on the network to browse freely.
Scenario:
- LAN 1, Subnet
192.168.1.0/24can access all websites 192.168.1.100(Client A) is restricted towww.zyxel.comonly
Solution:
Go to Configuration > Security Policy > Policy Control and add the following rules in the exact order listed:
Rule
From
To
Source
Destination
Action
Rule 1
LAN1
WAN
192.168.1.100www.zyxel.comAllow
Rule 2
LAN1
WAN
192.168.1.1–192.168.1.99Any
Allow
Rule 3
LAN1
WAN
192.168.1.101–192.168.1.254Any
Allow
Rule 4
LAN1
WAN
192.168.1.0/24Any
Deny
Before configuring the rules, go to Configuration > Object > Address/GeoIP > Address to create the address objects required for the rules above.
Note: Ensure that Client A (
192.168.1.100) is assigned a static IP address so that the policy is applied consistently.Zyxel_Judy
0 - LAN 1, Subnet
Categories
- All Categories
- 442 Beta Program
- 3K Nebula
- 223 Nebula Ideas
- 129 Nebula Status and Incidents
- 6.6K Security
- 633 USG FLEX H Series
- 355 Security Ideas
- 1.8K Switch
- 85 Switch Ideas
- 1.4K Wireless
- 54 Wireless Ideas
- 7K Consumer Product
- 300 Service & License
- 493 News and Release
- 92 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 88 About Community
- 109 Security Highlight
Freshman Member
Guru Member
Zyxel Employee