Switch to full style
Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems
Post a reply

prevent access only to www proxy service

Dec 04 04 5:36 pm

Hi..
I am using Wingate 5.23 build 901.
I want to block certain users from accessing internet thru wingate proxy. I have added their IPs in ban list but this also prevents them to access machine (on which wingate installed) completely. They are also being blocked to get mails from my server ( i m using mademon mail server on same machine).

Please let me know how I prevent access to just www proxy server service. I am not using winnt database. I use winngate user database.

thanx
hiten

Dec 04 04 5:45 pm

Set a Policy for "Everyone" in the WWW Proxy Service.

In the list of "Excluded" locations you can add the addresses of people you do not want to access the WWW Proxy.

In the list of "Included" locations you can add the addresses of people you do want to access the WWW Proxy.

If you follow this way you should set "Default (System) Policies" to "Are IGNORED".

Dec 05 04 12:11 am

Hi pascal,

thanx for quick reply.

I was able to perform the same. But there is one more problem there.

I have to add each IP in include or exclude list. Is there any way that we just enter allowed IPs in include list and rest all the ips are treated as excluded or vice versa.

Can we enter the wildcards here.

It is very lenghty process to enter each IP in include/exclude list as there are more than 150 machines.

Hiten

Dec 05 04 9:44 am

I don't have the helpfile with me at home - but there is a way to mask it / use wildcards. Check in the helpfile?

Dec 06 04 8:50 am

WinGate HelpFile wrote:In order for the right to be granted, the IP number of the computer that the user is on must match at least one Included location, and must not match any of the excluded locations.

An IP Filter can contain wild cards, allowing you to specify a range of IP addresses.

By using wild cards (e.g. the characters ‘?’ and ‘*’) you can tell WinGate to ignore certain parts of the IP address when comparing against the location restrictions.

These wild cards work in the same way as they do for DOS filenames, so if you are familiar with this then this concept should be easy.


That explains (a) how it works and (b) how the wildcards work. Using the filters you won't have to specify all 150 - simply add the entire range as a filtered list in "Included" locations and add the (Hopefully smaller) list in "Excluded" locations.
Post a reply