I have w2k3 network with around 50+ users, DSL internet and Cisco 1841 with SDM. Everything works fine but I would like to block HTTP access for some staff members but they require access to POP3/SMTP emails. I would like to know what are the best practices for this? In our old Nexland Internet sharing box, we used to allow/block MAC addresses for access to HTTP/EMAIL etc.
Anyone want to share the expertise in this matter?
Thank you in advace, Hemal
I'm not a Cisco expert, but usually the configuration is flexible enough so that you could block common HTTP ports (80, 443, 808x, etc) by MAC or IP address if you like. That's not really a flexible method though.
What I would do is:
Now you have fine-grained control on who is allowed access to HTTP, and you don't have to play with router config every time you add users, computers, etc. I suggest also that you always allow access to sites that provide automatic updates (like Windows Updates, updates from your AV vendor, etc).