Question : help blocking employees from accessing facebook

Hello,

I work for a small office doing data entry.  Occasional Facebook viewing is ok but we have a few employees who are abusing it and not getting any work done.  

I've blocked facebook.com by editing the hosts file.    But is there a way to go further and instead of blocking ALLOWING?  like a hosts.allow?   this is on a windows machine.  Windows vista on a windows network.  

Thank you,

Answer : help blocking employees from accessing facebook

To monitor, I like to use simple NTOP. http://www.ntop.org
Get an underpowered PC with 2 NIC's in it. linux and Ntop, and plug one NIC into a mirror port on the switch that connects to the firewall. Access the web pages/reports through the other NIC
Or something like Squid/DansGuardian on a linux box using WCCP redirect on the PIX to filter outbound.
Or Windows ISA server in one-legged Proxy mode and set all user's PC's to force proxy use. Use the PIX to block all outbound http except from the proxy's IP.
What version PIX? If it is 515e you can run up to 8.0 code on it and use advanced http filtering to block specific websites, while bypassing the filter for specified internal hosts..
Random Solutions  
 
programming4us programming4us