The fundamental step in maintaining a secure network environment is the creation of an Internet access policy. Kerio Control allows administrators not only to create a general Internet traffic policy for the local area network, but also define and enforce Internet access restrictions for each individual user.
User management
With WinRoute Firewall, a "user" is defined in the following ways:
- Individual user name with password
- User group
- IP address or computer name
- Entire network
Individual users may be forced to log into Kerio Control before they are allowed to access the Internet.
Managing users through internal user database
User accounts are stored either in an independent Kerio Control's internal user database or – for larger installations – in a remote Microsoft Active Directory server. Both databases can also run concurrently.
Managing users through Active Directory
Introduced in Windows 2000 Server, Active Directory allows administrators to centrally manage and share information on user accounts and network resources. Active Directory allows different services to access user information from a single location.
Support for Active Directory allows Kerio Control to access this user database in real time and authenticate users without storing passwords locally. It is not necessary to manually synchronize passwords for each user at the firewall. Any changes made in Microsoft Active Directory are automatically reflected in Kerio Control.
Access rights management
The administrator can assign different restrictive access rights to each user. For example, some users can only access internal webpages, while others can use only email. These rights are configurable according to a schedule so that they may be applied only during specified time intervals.
User traffic quota
Some users download a lot of files, listen to Internet radios, and share family movies with others. Excessive Internet browsing by one user often affects the usability of the Internet connection for the rest of the team.
To put a cap on heavy users, administrators may impose user traffic quotas. Administrators have a few options:
- Quota for upload, download or both
- Quota per day or per month
- Or any combination of the above
When the quota is reached, Kerio Control will send an email warning to the user and the administrator. Optionally, Kerio Control can block the guilty user for the rest of the day or month.