Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Block internet access for AD groups authenticated users in XG firewall

Hello,

i want to block internet access to any user profile in XG device ( i dont want to block by IP since i still want to give internet access to other users on the same station )

the two logical ways are either to create a new rule to reject wan access to user profile as source or in client list where i can deny all internet traffic 

none of the these solutions block internet access

all users are imported from AD and STAS collector is installed on DC .

any hint what could be the solution to apply

 

 

thanks



This thread was automatically locked due to age.
Parents
  • Hi  

    You may two options 

    1. Create a Group for users who does not need internet access by setting Application and Web Policy set to Deny All on Group policy.

    2. Create a Rule and select the users/group and set action of the rule to 'Deny'.

    Kindly note, you may need to check if the traffic is not going through any other rule and position the rule on top to be sure. 

Reply
  • Hi  

    You may two options 

    1. Create a Group for users who does not need internet access by setting Application and Web Policy set to Deny All on Group policy.

    2. Create a Rule and select the users/group and set action of the rule to 'Deny'.

    Kindly note, you may need to check if the traffic is not going through any other rule and position the rule on top to be sure. 

Children