How to Block Porn sites in school LAN ?

Re: Want to Block Porn sites in school LAN

@Firebird
PC's are connected as below
b) LAN PC's ==> Proxy (some other proxy server) ==> Untangle ==> Router ==> Internet
That's where your problem is. Your network is setup such that Internet connections bypass Untangle. Also, FWIRC but I may be wrong, Untangle does not correctly use an upstream proxy and therefore will have problems if you try to place the upstream proxy between Untangle and Internet. IPCop can use upstream proxies via an addon (Advproxy).

So theoretically i need to do is
a) Banned outbound packets which are going to proxy server.(so students will not able to use ISP's proxy server)
b) Now filter packets using untangle server. And forward filtered packets to ISPs proxy server.
c) Reroute the incoming filter from proxy server to respective PC's

With regard to a) above Internet bound packets will have to pass through Untangle/other firewall if they are to be manipulated. As you have indicated in your reply, they do not, therefore they cannot be.

The solution you are trying to implement, using the network layout you have, with packet inspection and filtering is way too complex without a DPI device/software. Remember, the more complicated something gets the more difficult and costly it is to implement and eventually more points of failure.

With regard to b) and c) that's how Network Address Translation (NAT) works. Untangle, IPCop and routers in NAT mode do NAT'ing and will allow you to do exactly what you want in b) and c) above as long as you ensure all requests flow through them (i.e.) my layout a).

Using this solution i will able to achieve web filtering without deep packet filtering. But is this theoretical solution is practically implementable.?
Without a network layer firewall which can do DPI or an application layer filter that can do DPI (ipfire.org which is a fork of IPCop appears to be able to do layer 7 filtering), the answer is no.

I'd recommend you go with layout a) with IPCop forwarding to your ISP proxy. If you decide to go with IPCop and this network layout I will be able to help you along. Post on this thread before you get started with IPCop and I will give you some pointers to getting it implemented correctly.

With Ipfire I could offer some assistance, but I may not have all the answers. With anything else, you are on your own or maybe some other members on this site will help.

Doc Holliday's suggestion would also work for you, but has to be implemented the way it is described in his post. An Asus router is not all that expensive, but I don't know your budget.

A Happy Diwali to you too and post back on this thread if you still need assistance once you get back.
 
Re: Want to Block Porn sites in school LAN

Gaurish said:
Are you out of your mind? these are school kids you are encouraging
We all started it at school,don`t we?Nothing is really wrong with it.
 
Re: Want to Block Porn sites in school LAN

Firebird said:
now a days kids can install xp and boot using pen drives. They also know how to change ip addresses and proxy etc.

Wow...I'm sorry I have nothing helpful to contribute here but kids booting off USB devices to surf p0rn; you have got some smart kids there ... death to 'encounter with the n00bs' thread. Might as well channel such clever kids to some positive PC activities.
 
Re: Want to Block Porn sites in school LAN

There are some porn filters that works even when traffic is being rerouted through proxy servers for example: HomeGuard Make sure you install it on the same host as the proxy server and it will automatically filter net traffic for all PCs auto.

Another thing to watch out for is encryption if the kids are using 'tunneling' through SSL you may want to consider disabling HTTPS (HTTP over SSL) this is also possible with the filter mentioned above however this will also block all web based email and any site that requires HTTPS for log in.
 
Re: Want to Block Porn sites in school LAN

In my college they use Fortinet Fortiguard all our efforts to by pass it are futile for the last three years..:( :@

see it in action

NeTLJ.jpg


0KHVW.jpg


KPfEO.png

some links found by googling are FortiGuard | Home

Fortinet, Inc. : Multi-threat Security Systems For Real Time Network Protection, Network Virus Protection, VPN, Intrusion Detection & Prevention
 
Re: Want to Block Porn sites in school LAN

meh just stick fake webcams in all corners of a room and put a sign saying "Anyone person caught watching porn will be banned from the computer lab".

Problem solved.
 
Re: Want to Block Porn sites in school LAN

Dayum ! ...then i dont belong here then !!

--- Updated Post - Automerged ---

Well i can bypass most securities myself :) i have done so in my school! ! i have looked at a testpaper before the test ,..... SORRY IF THERE IS ANYONE FROM MY SCHOOL HERE
 
Re: Want to Block Porn sites in school LAN

lolz at the mast thread title

i remember my school days
abey dont be harsh on school kids

:bleh:DESI MALU AUNTY HD:rofl:

sorry just could not stop myself:ohyeah:
 
Back
Top