Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

Killing off gaming on your network

Michael Mullins CNET News

Published: 04 Aug 2005 16:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Take advantage of Group Policy's Software Restriction Policies
Within the Local Security Settings and the Group Policy Settings, you'll find the often-overlooked Software Restriction Policies folder. As the name implies, a software restriction policy controls what software a user can and cannot run.

This is actually a group policy element that you can apply either to the domain controller (and users inherit the policy), or you can apply it directly to a workstation running Windows XP or Windows 2000. To change the Software Restriction Policy locally, follow these steps:

  1. Log onto the machine as Administrator.
  2. Click Start | Control Panel | Administrative Tools.
  3. Double-click Local Security Policy.
  4. Under Security Settings, expand Software Restriction Policies.

You'll find two containers under Software Restriction Policies: Security Levels and Additional Rules. The Security Levels container displays the two levels you can apply via policy rule, which are Unrestricted and Disallowed. The default is Unrestricted.

You can use the Additional Rules container to specify the specific software to allow or disallow; you can specify this by path, certificate, hash, or Internet zone. For example, if a popular game or unauthorised application has an executable called Hacker.exe, you can create a rule that disallows applications regardless of the installation path by using wildcards to denote the path.

Note: This is a powerful tool, so use appropriate caution. You can inadvertently lock out users from necessary applications.

Create a network policy
Perhaps the trickiest of all solutions, a network policy is useful for blocking the most common games on your network. At the network boundary going toward the Internet, you should only allow users to access specific ports. (The firewall or the router's access control list normally handle this type of thing.)

Typically, users only need outbound access to Web traffic (i.e., TCP ports 80 and 443). Exceptions can grow from that initial starting point, such as FTP access or IMAP and POP for external email servers.

By only allowing users to exit your network via specific ports, you're also blocking the ports that most online games require to operate.

Final thoughts
A company's network should only support those applications that are necessary for the business to operate. Allowing anything else opens the door to all sorts of potential security threats. To better protect your organisation's network, make sure users game at home and leave work at the office.

Mike Mullins has served as an assistant network administrator and a network security administrator for the US Secret Service and the Defense Information Systems Agency. He is currently the director of operations for the Southern Theater Network Operations and Security Center.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
95 out of 162 people found this useful



Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Using Bluetooth on Linux

I have mentioned before that I use a number of Bluetooth peripherals with my portable computers. This is one of those things where, the more I use it the more I like it. I've now... More

Post a comment

Toshiba JournE Touch

Look around the room at any meeting these days and you see the back of a lot of laptop screens, with as many people catching up on email as taking notes or doing relevant research.... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters