Is it possible to do time Based access restrictions by either mac or ip address? I need to limit the kids pc surfing and online game playing without affecting mine.
If you are running v6.10x then you can use IP address restrictions. Here is what I have done. I enabled all proxies and allowed minimal filter rules for the group to be dropped. I setup times to allow and time to dis-allow, make sure there is no overlap. Filters allowed for the kids are ftp, ntp and the tcp-udp-all. I created a "good guys" group which was allowed 24 hour access, in both filter rules and the http proxy. I also enabled the https part of the http proxy as well.
In general I drop everything bar the good guys group, that way if the kids or their friends are smart enough to add devices to the network they are barred by default.
I also use DHCP to assign addresses, but have a limited range for the dynamic addresses and another range withgin the same sub-net for all devices as trhey appear on the network.
I have probalby made it sound more complex than it is, but I hope you can understand it.
If you are running v6.10x then you can use IP address restrictions. Here is what I have done. I enabled all proxies and allowed minimal filter rules for the group to be dropped. I setup times to allow and time to dis-allow, make sure there is no overlap. Filters allowed for the kids are ftp, ntp and the tcp-udp-all. I created a "good guys" group which was allowed 24 hour access, in both filter rules and the http proxy. I also enabled the https part of the http proxy as well.
In general I drop everything bar the good guys group, that way if the kids or their friends are smart enough to add devices to the network they are barred by default.
I also use DHCP to assign addresses, but have a limited range for the dynamic addresses and another range withgin the same sub-net for all devices as trhey appear on the network.
I have probalby made it sound more complex than it is, but I hope you can understand it.