We have launched the new version of the DrayTek website, and this content is no longer being maintained.
You will find more information on our new site; however, we will keep this page for a few months.

[Vigor3900] How to block social networking websites during working hours?

To manage the users, the administrator may set a specific IP range for the employees to use, which is 192.168.1.11 to 192.168.1.20 in this example, and then set a firewall rule for the LAN clients from this range of IP address.

In this note, we demonstrate how to block employees from social networking websites with Web Content Filter (WCF) for a specific period of time, while the managers are able to access those websites without restriction.    

   

Configuring Vigor3900

1. Make sure your Content Filter License is activated. Go to Objects Setting >> Web Category Object >> Content Filter License, and check if the status of license is enable.

   

2. Create a Web Category Object to block social networking websites. Go to Objects Setting >>Web Category Object >> Web Category Object, click Add to create a new one.

  1. Enter Profile name.
  2. At Computer category, select Social-Networking.
  3. Click Apply to save.
   

3. Create an IP Object to presents employees' IP address. Go to Objects Setting >> Web Category Object >> IP Object, and click Add to create a new one.

  1. Enter Profile name.
  2. Select Address Type as Range.
  3. Enter Start IP Address and End IP Address as the Employees' IP address range.
  4. Click Apply to save
   

4. Create a Time Schedule for this policy. Go to Objects Setting >> Time Object, click Add to create a new one.

  1. Enter Profile name.
  2. Select Weekdays for Frequency.
  3. Enter the Start Time of working hours.
  4. Enter the End Time of working hours.
  5. Define the Weekdays.
  6. Click Apply to save
   

  Note: Remember to go to Online Status to check if the Current System Time in System Information is correct

5. Create a firewall rule to block employees from social networking websites during working hours. Go to Firewall >> Filter Setup >> URL/Web Category Filter. Click Add to create a new one.

  1. Enter Profile name.
  2. Enable this profile.
  3. Enable Filter Https.
   

  1. At Time Schedule > Time Object, select the profile we set for working hours.
   

  1. At Source IP > Source IP Object, select the profile we set for the employees' IP address.
   

  1. At Action Policy > Web Category Policy, select the profile we set to block social networking websites. Click Apply to save.
   

 

 

Verifying

For LAN clients whose IP address is in the range between 192.168.1.10 and 192.168.1.20, which should be the employees, they can not open social networking websites during working hours. In this period, when they try to reach social networking website like Linked-in, they will get the following message instead.

   

But after 18:30, those LAN clients would have no difficulty accessing the website.

   

On the other hand, there is no restriction on LAN clients from the range out of 192.168.1.11 to 192.168.1.20. They can go to any social networking websites anytime.

 

 

Trouble-shooting:

To ensure the Web Content Filter works as we expected, please check if there is any filter rule ahead that accept the packet already. Among all the firewall rules, the IP filter has the first priority. That means if the packet received matches any IP filter, the filter rule will be applied and the rest of the filters will be ignored. The Application Filter has the second priority, and then the URL/Web Category Filter. If none of the filters are matched, the Default Policy will be applied.

Was this article helpful?
11[Vigor3900] How to block social networking websites during working hours? has been viewed------ 11 ------times.