MCTS to MCITP , 70-351 , 70-089 , 70-236 , 70-640 , 70-642 , 70-646 , 70-630 , 70-285 , 83-640: Step by Step Configuration to Block a Website

Thursday, June 17, 2010

Step by Step Configuration to Block a Website

Step by Step Configuration of ISA to Block a Website

In order to Block a Website you first need to create a Block List and then use it in your ISA rule.
This Step by Step Configuration will help you to Solve your Problem.

First Create a Block List (URL Set) :


Open ISA Server Management , Click Firewall Policy , On Right Most Top you will see three Tabs namely Tools,Tasks and Help. Click on Tools Tab and Expand Network Objects
.
















Right Click on URL Sets and click New Set, The Following windows opens, give it a name and enter the URL of website that u need to block.

















A new URL Set is created, Click Apply to sace the Changes.

















Now Click on Task Tab and Create a New Access Rule :

















Click Next , then select Deny :

















Click Next and Add the Following Protocols :

















Click Next and now add the Source to which you need to apply the rule from ( in most cases its internal )

















Click Next and Add External to the Destination List.


















Click Next and add the users you need to apply this rule for. You can also Add users from you Domain but for that you need ISA to be a Part of that Domain. Click Next and Finish.
Click Apply to Save the Rule .



















The rule must be on Top in order to Work Properly because ISA Access rule works the same as Access lists in Router. See the hightlight rule which is on Top named "Blocked Website".

















Now we will check this Rule on a Client machine,  Open any browser and enter the Website Address i.e www.facebook.com and see what happens.User must get the following message.


















Technical Information (for support personnel) 
Error Code: 502 Proxy Error. The ISA Server denied the specified Uniform Resource Locator (URL). (12202) 
IP Address: 172.16.0.1 
Date: 6/17/2010 5:50:17 AM [GMT] 
Server: isatest 
Source: proxy 


Note the Technical Information that tells you that the specified Address is denied by ISA.

Your Rule is now Created and No one can Access the Specifed Website.

Cheers,

Himayat Ullah Khan ( Cisco Certified Network Associate )

No comments:

Post a Comment

Use full comments are highly appreciable.

Please do not post irrelevant Messages.

Thanks.

Note: Only a member of this blog may post a comment.