This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to use multiple AD groups for web filtering.

We have created two AD groups 'Allow gmail' & 'Allow facebook' and imported both into Sophos. The user U1 is the member of both groups and the primary group is 'Domain Users' in AD. Then we created two separate web filter policies for  'Allow gmail' & 'Allow facebook'. When the user U1 logon only the 'Allow gmail' is applied and access to facebook is blocked. If we remove U1 from either of the groups, the remaining policy works fine. So, How can keep U1 member of multiple AD groups and apply the corresponding web-filter policy for each group. 



This thread was automatically locked due to age.
Parents
  • Hi Vinod,

    it's very easy to do.

     

    Generate one proxy policy with different rules.

    For Example

    Rule one, that is limited to the group STANDARD with the Activity “limited access” and action allow.

    Rule two, that is limited to the group FACEBOOK with the Activity “limited access” & “facebook access” and action allow.

    Rule three, that is limited to the group GMAIL with the Activity “limited access” & “gmail access” and action allow.

     

     

    Put USER1 in ActiveDirectory group STANDARD, the USER2 in group STANDARD AND FACEBOOK and the USER3 in STANDARD & GMAIL.

     

    So USER1 have standard access, the USER2 have standard access + Facebook and USER3 have standard access + Gmail.

     

    Did a setup like these some hours ago.

     

    Alexander Fuchs

     

    IT System Admiral

    IT Technology Senior Evangelist

Reply
  • Hi Vinod,

    it's very easy to do.

     

    Generate one proxy policy with different rules.

    For Example

    Rule one, that is limited to the group STANDARD with the Activity “limited access” and action allow.

    Rule two, that is limited to the group FACEBOOK with the Activity “limited access” & “facebook access” and action allow.

    Rule three, that is limited to the group GMAIL with the Activity “limited access” & “gmail access” and action allow.

     

     

    Put USER1 in ActiveDirectory group STANDARD, the USER2 in group STANDARD AND FACEBOOK and the USER3 in STANDARD & GMAIL.

     

    So USER1 have standard access, the USER2 have standard access + Facebook and USER3 have standard access + Gmail.

     

    Did a setup like these some hours ago.

     

    Alexander Fuchs

     

    IT System Admiral

    IT Technology Senior Evangelist

Children
No Data