Allow certain URLs only for a specific user

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Allow certain URLs only for a specific user

L1 Bithead

Is there any way to restrict a certain user to only a few websites?

There is URL filtering but I believe that is global and I wanted for only one user

10 REPLIES 10

L6 Presenter

You just need to create a new URL filtering profile and apply to that user.

Thanks for your response, when I create the URL filtering profile only allows me to include the URLs I want to allow/block, there is no particular section where I can select a user. Please correct me or guide me if I'm wrong

You will need to define a security rule under the Policies tab.  This rule should match on source=user action=allow and attach the URL filtering profile to this rule.  Make sure this new rule is positioned above any rule that may match on the user.

 

Thanks,

Ok thanks. So when I create new security policy, I go to the users tab and there's only one user list for all users. I'm guessing I can manually type the domain/userID here.

 

Just to confirm, I would create a new URL Filtering profile, allow the URLs I need to allow. Then create a new security profile (and position is #1 probably), the rule would be source (LAN zone), user (manuallty type a username), URL category I created and apply it.

 

Hoping that's it


@MohammedL wrote:

Ok thanks. So when I create new security policy, I go to the users tab and there's only one user list for all users. I'm guessing I can manually type the domain/userID here.

 

- Yes, assuming userID is setup & working you should see listing of users and you can choose the user from the dropdown.   You shouldn't have to manually type in the userID.  Otherwise,  you will use source_address=IP_of_user to match.  

 

Just to confirm, I would create a new URL Filtering profile, allow the URLs I need to allow. Then create a new security profile (and position is #1 probably), the rule would be source (LAN zone), user (manuallty type a username), URL category I created and apply it.

 

In the security rule, you need to select the URL profile from the Profile Setting:

 

URL-profile.JPG

Hoping that's it


 

Thanks again. The usernames aren't setup, I only see a 'all user list', in that case like you said source IP, would that also be entered in the source tab?

 

Thanks.

you'll first need to configure UserID which will then populate your list of available users

 

please read this article to help you set that up: Getting Started: User-ID

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Yes, the source tab will let you define the IP address for the source user, i.e 192.168.5.5.

Ok I'm sorry to ask you again.. Do I have to necessarily create an object for that one IP address or can I once manually type the IP there?

I would create a new address object.

  • 5782 Views
  • 10 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!