Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Hello

Hello

Plz how can i bloc acces to the internet for NON-Aactive directory, or Local User.

I already import my AD user and make the policy for only AD User, and check the "Match known users is selected"

But i see that all PCs from the local subnet, (even if AD user or local user) can get acces to the internet

help plz



Edited Tags
[edited by: Erick Jan at 1:05 AM (GMT -7) on 16 Sep 2022]
Parents
  • You can achieve this in various ways, Navigate to Configure > Authentication > Users, select the user and set Access Time as Denied all the time. You can also create a Firewall rule on the top with Identity set to "Match Known Users" , select the users for which the access has to be denied and set the Web Policy and Application Control as "DENY ALL"

    Let me know if that works for you.

  • Hello

    Thank you very much for your answer

    I can give access or deny to any Active Directory User, for users there is no problem, for exemple i can give internet access to "ahmed" but not to "khaled" , my real problem when i connect to the network  a local machine wich it's not joined to the Domain controller, this machine can connect to the internet even if i checked the "Match Known Users"

  • Firewall Rules with "Match Known Users" will only allow the traffic for authenticated user. You will have to authenticate the user using Captive Portal or other method.

  • i add a firwall rule at the "top" like this picture:

    Now only AD-User can get access to the internet, and others like local user they can't access to the internet.

    But when i login with a local user, the browser doesn't ask me to enter login/pass even if i checked for "Captive Portal"

Reply
  • i add a firwall rule at the "top" like this picture:

    Now only AD-User can get access to the internet, and others like local user they can't access to the internet.

    But when i login with a local user, the browser doesn't ask me to enter login/pass even if i checked for "Captive Portal"

Children