The 7 Best Internet Filters of 2022 (Tech Review)

The best internet filters: block websites, apps, and more

Want to block distracting websites, monitor internet use, and keep your network secure against web-based threats? This list of the best internet filters covers website blocking solutions that are suitable for businesses, parental control, Mac users, and more.

These website blockers span across parental control apps and browser extensions for home users that want to easily block sites, software for small businesses that want to prevent access to high-risk and distracting sites, and enterprise-level website blockers with advanced security features.

Notes: 

  • Prices are in USD unless otherwise specified
  • Each section includes a “Last Updated” notice to reflect how recent the data is

What Are Internet Filters?

An internet filter—also known as a “web filter” or “website blocker”—is an internet content restriction tool that restricts access to websites based on parameters such as URLs, web content categories, IP addresses, and keywords.

These tools are used to block distracting websites such as social media, prevent access to sites with inappropriate content such as pornography, and enforce company internet usage policies.

Depending on the vendor an internet filter can be as simple as basic website blockers or include advanced features such as web content category filtering and application control. 

When a blocked site is visited the user is typically presented with a block screen message that indicates why the website is blocked.

Types of internet filters:

  • Parental control apps that families use to restrict the internet usage of their children
  • Web filtering software that businesses and schools install on their endpoints to uniquely restrict users and computers
  • Personal internet filtering tools that individuals use to improve their focus time and restrict their own access to inappropriate content.
  • Firewalls that govern what data packets are sent and received within a network
  • DNS web filters that restrict internet access for devices that connect to a specific network

The Best Endpoint Internet Filter For Windows

Last Updated: 13 April 2022

BrowseControl

BrowseControl is an easy-to-use web filter that helps organizations enforce policies, improve productivity, reduce bandwidth consumption, and meet compliance requirements – no matter where their users are located.

With BrowseControl you can ensure a safe and productive environment by blocking high-risk, distracting, or inappropriate websites, improve network performance by blocking bandwidth hogs, and prevent users from using unsanctioned applications and software-as-a-service providers

BrowseControl’s security policies are enforced by a software agent that is installed on your user’s computers. This allows the solution to continue blocking websites and applications even when computers are taken off-site.

BrowseControl’s central console allows you to configure your security policies from the convenience of a web browser. 

With BrowseControl you can Block or allow websites based on URL, category, domain, or IP address, assign custom policies for each group of computers or users, prevent users from launching specific applications, and block network ports to reduce the attack surface of your network

There are three key methods for blocking websites with BrowseControl:

The Blocked List allows you to block specific websites based on URL, domain, or IP address

Category Filtering allows you to block millions of websites across over 100 content categories including pornography, social media, and virus-infected sites.

and finally, you can use the Allowed List to allow specific websites that would otherwise be blocked based on their category, or for the greatest security and control you can block all websites except for those that are on the Allowed List.

When your users try to visit a blocked website they can either be presented with a custom warning message or directed to another site, such as a page with a reminder of your organization’s internet use policy.

With BrowseControl’s App Blocker you can prevent your users from launching specific applications.

Simply select the group you would like to restrict, enter the Original Filename of the application to the Application List, and add it to the blocked applications list.

When the user tries to launch the blocked application they can be presented with a custom warning message that alerts them of the restriction.

BrowseControl is best used in tandem with our computer monitoring software BrowseReporter. Using both solutions provides the visibility and control you need to ensure that your organization’s computers are being used appropriately.

Don’t let internet abuse run rampant in your organization. Take back control over web browsing with a free trial of BrowseControl.

Get started today by visiting CurrentWare.com/Download

If you have any technical questions during your evaluation our support team is available to help you over a phone call, live chat, or email.

Thank you!

Overview

BrowseControl is an easy-to-use web filter that helps organizations enforce policies, improve productivity, reduce bandwidth consumption, and meet compliance requirements – no matter where their users are located.

With BrowseControl you can…

  • Ensure a safe and productive environment by blocking high-risk, distracting, or inappropriate websites
  • Improve network performance by blocking bandwidth hogs, and…
  • Prevent users from using unsanctioned applications and software-as-a-service providers
  • BrowseControl’s security policies are enforced by a software agent that is installed on your user’s computers. This allows the solution to continue blocking websites and applications even when computers are taken off-site.

Platforms & Deployment Options

BrowseControl is exclusively available on Windows. It supports Active Directory import and sync that allows you to manage your users with your existing organizational units. 

BrowseControl uses a software client to enforce internet use policies on devices no matter which network they are connected to, making it the ideal solution for protecting remote workers. 

BrowseControl has been verified as Citrix Ready. It can be installed on premises or to the cloud on a self-managed cloud virtual machine

Pros/Cons

Pros
  • Internet use policies can be customized based on user and computer groups; it integrates with Active Directory to simplify user management
  • At $3.99 PUPM it’s the best value web filter when compared to those with a similar feature set
  • Integrates with BrowseReporter to collect internet and device usage data
  • Easy-to-use interface and operator accounts allow for trusted employees to adjust or disable blocking as needed
Cons
  • Only available for Windows machines
  • Requires a software agent to control internet use
  • The search engines safe browsing feature only works on Google

Price

BrowseControl is a module within the CurrentWare Suite. When purchased as a standalone module its pricing starts at $3.99 per license per month, paid annually. 

The full CurrentWare Suite starts at $8.99 and provides additional modules for internet use monitoring, data loss prevention, and remote PC power management. 

Discounts are available for prepayment and bulk licensing, managed service providers, and nonprofit/educational organizations.

A free trial of BrowseControl is available for 14 days and 10 computers.

Learn More: BrowseControl pricing and licensing FAQ

Key Features

BrowseControl’s central console allows you to configure your security policies from the convenience of a web browser. 

With BrowseControl you can…

Block websites based on URL, category, domain, or IP address

Screenshot of category filtering window from BrowseControl web filter. Porn and social media categories blocked.

Assign custom policies for each group of computers or users

BrowseControl web filter screenshot with computer and user mode

Prevent users from launching specific applications

screenshot of BrowseControl's application blocker

and Block network ports to reduce the attack surface of your network

Screenshot of BrowseControl's Port Filter for blocking TCP/UDP ports

There are three key methods for blocking websites with BrowseControl:

  • The Blocked URL List allows you to block specific websites based on URL, domain, or IP address
  • Category Filtering allows you to block millions of websites across over 100 content categories including pornography, social media, and virus-infected sites.
  • And finally, you can use the Allowed List to allow specific websites that would otherwise be blocked based on their category, OR for the greatest security and control, you can block all websites except for those that are on the Allowed List.
Screenshot of BrowseControl's "Display Warning Messages" window with a message for users that visit a blocked website

When your users try to visit a blocked website they can either be presented with a custom warning message or directed to another site, such as a page with a reminder of your organization’s internet use policy.

Learn More about BrowseControl’s features

Reviews

”As a ‘novice’ I was able to set up with help from support in about an hour. Previous software took forever and didn’t work as advertised; this software worked right out of the box. It allows my workers to use the internet and make money for the practice without distraction/temptation to use personal websites/email/shopping.”

Gerard B., Office Manager, Capterra (2019)

“Browsecontrol is the best software for internet filtering. We can block specific websites and applications from the organization’s computer and internet. We can add and remove the restrictions instantly is a great feature. They have great customer support to solve our queries.”

Ajoob S., Engineer Trainee, Capterra (2022)

“We use Browse control and other CurrentWare products as an essential part of our security practices. I like the product, and it works great. We have utilized CurrentWare for the last eight years, and I’ve no complaints. Responsive support and willing to take feedback and suggestions. Highly recommended”

Anonymous Verified Reviewer, Capterra (2022)

The system works very well. Features like being able to provide a custom block screen are great. Being able to rename the system from the actual PC name helps to better identify the system in the admin interface. You can create a custom installer for client systems. It’s easy to update the client settings, and to import settings from an existing client to a new one.”

Ethan C., Director of Operations, Capterra (2022)

“The purchase and on boarding process was very smooth and customer support is very efficient . I had an executive who helped with the renewals although it was a non working day in his country , I would recommend it to anybody. The software is easy to install and was cheap to purchase and Cost wise very high ROI.”

Anoop P, System Administrator, Capterra (2022)

Support

The Best Internet Filter For Personal Productivity

Picture with text: How to Increase Productivity - CurrentWare. Photograph shows a hand demonstrating an upwards curve motion with an arrow following the index finger, simulating a graph

Cold Turkey

Last Updated: 13 April 2022

Overview

Cold Turkey is a personal productivity improvement tool that allows you to block distractions such as unproductive websites or applications until a certain time. It is used by people that want to improve their productivity by enabling distraction-free sessions for their projects.

With Cold Turkey, you can readily limit screen time, temporarily block any distracting website you want, and even block distracting apps.

There is a free version of Cold Turkey that only blocks websites, as well as a perpetually licensed paid tier that introduces added features such as app control, passwords, user-based filtering profiles, and internet scheduling.

Platforms & Deployment Options

  • ✅ macOS
  • ✅ Windows
  • ❌ Linux
  • ❌ Chromebook
  • ❌ Android
  • ❌ iOS
  • ✅ Browser Extension* 

Learn More: Cold Turkey System Requirements

*Firefox, Safari, and Google Chrome extension

Pros/Cons

Pros
  • Unlimited website blocking on both free and paid versions
  • The pro version is an affordable one-time payment
  • The pro version includes unblocking/uninstall protection
Cons
  • Does not block sessions on all browsers
  • Blocker needs admin rights for various reasons and there’s no way to install the app without it
  • Limited Website Categories available

Price

The free version of Cold Turkey allows you to block websites, set website exceptions (allow list), configure timed blocks, and view statistics on your personal internet usage.

The pro version (Blocker Pro) is only $49.00 CAD (~$38.84 USD) for a lifetime perpetual license, with only one purchase needed for all computers that you personally use. Students can request 20% off by going to the support page and clicking the link in the FAQ.

The pro version includes the following additional features:

  • Block applications
  • Scheduled blocks
  • Application password
  • All locking features
  • Custom user selection
  • Breaks and allowances

Features

Block Domains

Adding facebook.com to the block list will block all web pages on Facebook including subdomains.

Web Category Filtering

Block websites based on predefined content categories.

Block and Allow Specific URLs

Some web filters require you to block an entire website, which is troublesome if you want to block a website while allowing specific pages in that site. 

With Cold Turkey you can granularly block or allow specific URLs in addition to blocking an entire website. You can also allow only a category of websites.

Block The Entire Internet

If the internet as a whole is a distraction you can prevent internet access entirely, forcing you to only focus on non-internet resources. 

Custom Block Screen

When a website is blocked, you’ll see a motivational quote to remind you that you should be working. The block page can be customized in the pro version.

App Blocker
  • Block Applications by File: Select exe files on Windows or the app in macOS to block those desktop apps from launching
  • Block Application Folders: Selecting a folder to block will block all exe files or other apps located in that folder from launching
  • Block Windows 10 Apps: Most apps from the Microsoft Store can be blocked by selecting it from a list.
  • Block Window Titles: On Windows, you can block apps by window title. This also applies to website titles, but instead of your browser being blocked only the website will be blocked.
Scheduled Blocks 
  • Blocking Calendar: Create a website blocking schedule that will automatically repeat every week
  • Pomodoro timers: Pomodoro timers alternate the site blocking on and off while you work to allow for breaks at predefined times
  • Allowances: Allowances are timers that let you use blocked websites and apps until the allowance is used up
Block Your Entire Computer

Lock, log off or shut down your computer for a set period of time. This feature makes it easy to schedule time away from your workstation for a break or a quick walk.

Uninstall/Unblocking Protection

In order to be an effective personal productivity tool, Cold Turkey provides web filter bypass protection to prevent users from simply disabling the filter and resuming their unproductive habits.

  • Timer: Prevents changes to your filtering policies until a specified time in the future
  • Random Text: Requires you to type out a series of randomized characters to disable the block
  • Time Range: Prevents changes or only allows changes to the block between certain times of day
  • Restart: Requires you to restart your computer in order to unlock the block.
  • Password: In the pro version, a password can be used to lock the block. This can be a useful feature for parents or someone with an accountability partner.
  • Block Time Changes: This feature prevents you from changing the system time to circumvent a block.
  • Block The Task Manager: In most cases, the block will continue to work even if the processes are stopped. You can block the task manager just to be safe though!
User Selection (Pro)

In the free version of Cold Turkey blocking policies will apply to the computer, including other users of the device. With the pro version you can enable user-based blocking to apply the restrictions to one user without affecting other users.

Note: As of April 2022 you cannot apply different filtering policies to each user with Cold Turkey.

Reports On Time Spent Browsing

With the Statistics Tab you can keep track of what websites and applications you spend time on so you can better understand which websites are distracting you.

Reviews

“Super flexible and hard to trick”

Anonymous, AlternativeTo.net

“It helped me avoid lots of distractions!”

alxh28, AlternativeTo.net

“The greatest blocking distractions software ever.”

Helldorado, AlternativeTo.net

“Cold Turkey Blocker now costs double what it was when I first used it a couple of years ago. In addition, coupons are no longer offered unless you’re a student. The price hike is consumer unfriendly and I will have to think about continuing my support of this app.”

Jake Salzer, TrustPilot.com

“Easy setup and I love all the included lists of websites. You can block porn, distractions, news, movies and videos, games, and a variety of other things with a click of a button. Also, the scheduled blocks are easy to set up and really help a lot. Great customer service and everything was thought of. For example, the cold turkey website has a built-in timer to make sure that you can’t disable the program.”

Natanel Rozic, TrustPilot.com

Support

  • ✅Email/Help Desk
  • ✅ Knowledge Base
  • ❌Phone Support
  • ❌Live Chat

As Cold Turkey is a consumer-grade product that is independently developed and supported by a single person the support offered is not as robust as what would be expected from an enterprise-tier product.

That said, the Cold Turkey website offers a convenient FAQ, user guide, and contact form that gets responded to within a few business days. These support options are perfectly suitable for a simple consumer-grade product like Cold Turkey. 

The Best Internet Filter for Internet Security

Forcepoint Next Generation Firewall (NGFW)

Last Updated: 13 April 2022

Overview

Forcepoint (formerly Websense) provides a class of security solutions known as “Next Generation Firewalls” (NGFW). 

These products build upon the protocol/packet filtering capabilities of traditional layer 3/layer 4 firewalls with added features such as deep-packet inspection, intrusion prevention, and added intelligence about potential threats to the network.

Forcepoint’s NGFW provides security and visibility across physical, virtual, and cloud systems with an integrated firewall/VPN, IPS, and layer 2 firewall. 

Due to Forcepoint’s NGFW’s complexity of deployment and the cost of implementation it is best suited for large enterprises with a significant IT budget and the resources to dedicate IT staff to deploying and managing the solution.

See Also: Forcepoint alternatives for internet filtering and employee monitoring and Kaspersky alternatives

Platforms & Deployment Options

Forcepoint NGFWs can be deployed in a variety of ways (e.g., physical hardware appliance, virtual/cloud appliances, etc), with multiple products managed from a single console

They support cloud infrastructures such as Amazon Web Services, Microsoft Azure, Google, Oracle, IBM Virtual Appliance x86 64-bit based systems; VMware ESXi, VMware NSX, Microsoft Hyper-V, and KVM 

The Forcepoint VPN client is available for Microsoft Windows, Android, and Mac OS.

Pros/Cons

Pros
  • Robust NGFW that combines multiple security products into a single vendor
  • Central management of multiple Forcepoint products
Cons
  • Cost-prohibitive pricing for non-enterprise customers
  • Reviews indicate that support is lacking, though improvements have been made
  • The complexity of the solutions requires a dedicated IT staff member to implement and manage them

Price

Forcepoint has not provided pricing information for this product or service. There is a 30-day free trial available as well as add-ons such as URL Filtering, which is a separate subscription (listed as $14.99 per user/year on CDW).

Due to the wide variety of deployment options, add-ons, and the unique configurations required between different enterprise networks it is difficult to ascertain the exact price of Forcepoint’s NGFW.

For example, the Forcepoint Next-Generation Firewall 6205 Appliance is listed for $126,381.00 on CDW but some enterprises may require additional virtual/cloud deployments to manage their volume of traffic.

A pay-as-you-go Amazon Machine Image of Forcepoint’s Next Generation Firewall version 6.10.0 is available on the AWS store for $1/hour, though exact pricing will largely depend on usage.

Based on a purchase price of $145,395, NSS Labs gave Forcepoint an estimated $240,533 total cost of ownership (TCO) per 3 year period, making the TCO $6 per protected Mbps.

Features

This section will provide highlights of Forcepoint’s NGFW. Forcepoint provides a specifications PDF with further details that is current as of 23 Feb 2022.

Malware Detection and File Control

Forcepoint’s NGFW detects malware over the FTP, HTTP, HTTPS, POP3, IMAP, and SMTP protocols.

Its file filtering and file reputation scanning supports 200 file types across 19 file categories, allowing organizations to detect and block known malware threats in files. Some appliances include a local antivirus scanning engine as well.

It also includes sandboxing as both a cloud and on-premises service to analyze the behavior of suspicious files.

Application Control

Block endpoints from launching applications.

Intrusion Prevention System (IPS)

Forcepoint’s IPS monitors networks for potential indicators of compromise, alerts system administrators when a potential threat is found, and provides remediation such as closing access points.

Virtual Private Networks (VPN)

With Forcepoint’s NGFW you can establish Policy-based VPNs and Route-based VPNs, allowing for a secure Site-to-Site VPN to route traffic through.

Data Loss Prevention

Forcepoint’s DLP features include application-layer exfiltration protection such as automatically allowing/denying network traffic originating from specific applications on PCs, laptops, servers, file shares, and other endpoint devices.

URL Filtering (Separate Subscription)

The URL filtering add-on is a separate subscription that allows admins to block or allow websites with custom or imported URL lists.

Similar Product: URL Filtering in BrowseControl

Deep Packet Inspection

The NGFW’s Deep Packet Inspection enables the decryption of encrypted traffic so that related security features can analyze the contents of encrypted packets. It includes granular decryption of SSL/TLS traffic so admins can ensure that sensitive websites such as banking and healthcare sites are not decrypted.

Centralized Management With Remote Access

Fortinet’s central console provides the ability to manage large quantities of firewalls and fleets of firewalls at scale from a single dashboard. The dashboards can be accessed remotely.

Reviews

While Fortinet’s NGFW is a versatile and robust security tool, there has been critical feedback regarding their support, with the most critical reviews spanning between 2013-2016. While it appears that their support has improved since then more recent reviews continue to indicate issues in terms of responsiveness, though it’s possible that not all of these admins had an applicable SLA with the vendor.

“If you are looking for a Web Filtering solution, you would probably be better off with something else that is more cost effective, more flexible, and has a tech support that doesn’t take a couple days to contact you, nor months to actually fix the problem despite the severity.”

Rick Castello, Spiceworks.com (2013)

“This could be a good product but support is so poor it is unbelievable. They clearly do not read the details of support ticket then ask questions for which the answers were included in the original support ticket. We have had a problem with internet filtering which effects Outlook and they have not been able to resolve the fault for 3 years.

The standard response is asking to provide wireshark traces even when they are not required. They usually only reply once in a 24 hour period, I think they aim to just shift the focus back on to the customer. We all are glad our contract ends before the end of the year. Avoid Forcepoint at all costs”

Origin IT, Spiceworks.com (2016)

“My overall experience has been good. Forcepoint has come a long way with their product and the features being made available over the next couple of versions are exciting and needed. The Forcepoint team has been very good to work with and they have shown remarkable improvement in customer service and technical support.”

David Stanfield, Spiceworks.com (2017)

“Pros: The software is very easy to set up and use once deployed. The user interface is pretty straight forward and pretty basic to use.

Cons: Forcepoint has really gotten worse with the years. Features could be a lot better and more granular. The solution is very expensive compared to their competitors and they make you pay extra for malware detection.”

Joevanne V., Capterra (2018)

“In our opinion, the FortiGate Next-Generation Firewall is a great and strong security solution that no other security solution can match. Our firm is satisfied with this platform because the admin console is easy to use, and the process of learning is also simple. The initial setups are relatively simple to complete. A next-generation firewall also facilitates the connectivity of our numerous branch offices. For branch communication, we’ve additionally put up an SSL VPN. It works better than other comparative platforms.”

Anonymous Verified Reviewer, Gartner.com (2022)

“The support is horrendous for what we pay. With 4-hour turn-around support, you’d think we wouldn’t get someone from overseas replying 5 days later with a KB article when I clearly stated I need remote help. Now going through another ticket, 4-hour turn around, was contacted to get remote help two days later at 11pm at night. I am furious.”

Kyle Lerner, Spiceworks.com (2014)

“Product works ok, but support is nonexistent and their in place upgrades NEVER work!. Which is why I’m trying to get support! Currently on hold at 61 minutes. Also on my cell phone trying to contact a manager to complain. Now being told by dispatcher that he can’t find his manager.

This is on an open case that I emailed assigned tech at 1PM that upgrade blew out my Websense Web Security. Called at 5PM as I didn’t get ANY reply back.

And the kicker is that when I first open this case, I was on hold for 1.5 hrs waiting for tech! I ended up calling from my cell and was able to reach a mgr that time to complain!!!

I REALLY REALLY wish there is a negative star option. I’d rate them at a -50! especially since it’s an hour over when I should have left work!!!!”

Jason Chan, Spiceworks.com (2014)

“Pros: The software helps you to keep your network secure. It also delivers performance for email and web traffic.

Cons: It is complex to configure. Also it is not very flexible. Transparent proxy is not possible. Proxy bypass rules have to be defined both it the proxy and in the firewall. That increases operational costs.

Reasons for Choosing Forcepoint Web Security: Our service partner gave this as only option.”

Anonymous Verified Capterra Review (2019)

Support

  • ✅ Email/Help Desk
  • ✅ Knowledge Base
  • ✅ Phone Support
  • ✅ Live Chat

In contrast to the reviews critical of Fortinet’s support, they do offer a wide variety of support options. According to their website they offer world-class Enterprise Support with an average call answer time of <5 minutes, 1000+ Fortinet technical and operational service experts on staff globally, and advanced Support options to align with your operations.

Support pricing is not publicly listed on Fortinet’s website; CDW lists the cost of technical support at $21,851.99 per year.

The Best Internet Filter For Mobile Devices

ManageEngine Mobile Device Manager Plus

Last Updated: 13 April 2022

Overview

In addition to offering Web Content Filtering on mobile devices, ManageEngine Mobile Device Manager Plus is a robust MDM solution that organizations can use to control and protect a wide range of devices including smartphones, tablets, laptops, desktops, and smart TVs. 

Core features such as containerization, app distribution, and remote data wiping enable BYOD policies without compromising security and privacy.

Platforms & Deployment Options

ManageEngine Mobile Device Manager PlusZ lets you manage several types of smartphones, tablets, laptops, desktops, and smart TVs. 

It supports multiple operating systems including Android, iOS, iPadOS, tvOS, macOS, Windows, and Chrome OS, making it an ideal solution for organizations that need to manage a wide range of mobile devices.

  • ✅ macOS
  • ✅ Windows
  • ❌Linux
  • ✅ Chromebook
  • ✅ Android Devices
  • ✅ iOS Devices
  • ✅ iPadOS
  • ✅ tvOS

Pros/Cons

Pros
  • Free edition that manages up to 25 devices
  • Perpetual and annual subscription options
  • Supports a wide range of devices
Cons
  • Convoluted device self registration process
  • Inconsistent email enrollment options for devices
  • Confusing UI with inconsistencies between tabs

Price

ManageEngine Mobile Device Manager Plus is available as a free trial for 30 days with unlimited devices. There is also a free edition that manages up to 25 devices, making it an ideal tool for small businesses.

They provide two paid tiers: Standard and Professional, each with their own set of features. A feature comparison table can be found here.

In addition to the pricing for the software itself, ManageEngine charges a separate fee for installation support and training.

  • Basic Training @ US$495
  • Installation & Setup + Training @ US$995
  • Onsite Training @ US$3995

To learn about pricing for ManageEngine Mobile Device Manager Plus, check out their pricing table.

Features

This section highlights the key features offered by ManageEngine Mobile Device Manager Plus. Different features are available between their standard and professional tiers. A full feature comparison is available in their Edition Comparison Matrix.

App Distribution & Control

Allow or ban which apps can be brought onto the company premises by employees. Lock down devices to run a single app or a set of apps. Prevent users from adding an unwanted browser extension to their bowser.

Web Content Filter

ManageEngine’s MDM Web Content Filter lets you control the web content that can be viewed on mobile devices with granular allow and block lists.

In addition to restricting or allowing URLs, the Web Content Filter supports the automatic restriction of websites that are known to have malicious content, allowing you to proactively block sessions that pose a risk to devices.

Prevent Third Party Cloud Backup

To help prevent data leaks to cloud services, you can restrict third party apps from accessing and backing up distributed documents.

Containerization

Containerization is a critical feature if you want to allow employees to use personal cell phones for work purposes (BYOD). 

With this feature you can create separate profiles for work and personal use, keeping all company-provided apps and data separate from the employee’s personal data.

With enterprise data stored in a separate encrypted container you can remotely wipe sensitive data and deprovision the device without affecting personal data outside of the container.

Reviews

Reviews of ManageEngine compliment its affordability when compared to other MDM solutions and robustness of features. On the critical side reviewers have noted that customer support is notably below their expectations.

“Pros: We recently implemented ManageEngine to easily manage our devices, create uniformity, and enhance security. After using the product for roughly a month now, we are very please with the results. Our team quickly embraced the idea’s and have had great success. The front end interface is clutter free and customizable. The backend offers an abundance of control and analytics. We love the ability to remotely manage our devices including remote control when needed. Lastly, small business prices under 26 devices is FREE.

Cons: Customer service lacks due to lengthy response times and language barriers. While chat support is available, it can be difficult to communicate the problem/solution. In addition, when phoning for support or sales, the phone system is difficult couple with extended wait times.”

Cody H., Capterra (2020)

“Pros: When you’re working with a smaller budget and can’t afford to shell out the multi-thousand dollar MDM solutions, ManageEngine MDM+ has your back. It’s got all the features you need including remote deployment of apps and geolocation.

Cons: In terms of assigning devices to users it can be a little confusing. Some users show up multiple times when assigning a device and it isn’t clear which one to assign it to. It’s also confusing where the users are tied to. Am I being charged per username creation? It isn’t really clear.”

Elliott W., Capterra (2022)

Support

  • ✅ Email/Help Desk
  • ✅ Knowledge Base
  • ✅ Phone Support
  • ✅ Live Chat

ManageEngine charges a separate fee for installation support and training.

  • Basic Training @ US$495
  • Installation & Setup + Training @ US$995
  • Onsite Training @ US$3995

The Best Internet Filters for Mac & Apple Users

Last Updated: 13 April 2022

Intego ContentBarrier for Parental Control on macOS

See Also: Net Nanny, https://www.netnanny.com/

Overview

In the modern digital age parents are increasingly concerned about what their children can access online. Intego ContentBarrier can block out entire categories of websites, so your children aren’t exposed to objectionable content. You can also set up a specific list of approved websites, so your kids can access them without accidentally running into the filter.

Platforms & Deployment Options

  • ✅ macOS
  • ❌ Windows
  • ❌ Linux
  • ❌ Chromebook
  • ❌ Android Devices
  • ❌ iOS Devices

Pros/Cons

Pros
  • Custom user profiles
  • Anti-Predator chat monitoring
  • See everything your children do on their devices; keystroke logging, screenshots, email alerts, and more
  • Affordable at $89.99 for 2 years
Cons
  • Lack of iOS support
  • Only for Macs
  • Limited social media coverage; ContentBarrier X9 doesn’t feature social media monitoring

Price

  • $49.99 for 1 Computer, 1 Year of Protection 
  • $89.99 for 1 Computer, 2 Years of Protection
  • $99.99 3 Computers, 1 Year of Protection
  • $184.99 for 3 Computers, 2 Years of Protection

Features

Internet Filtering & Monitoring
  • Blocks objectionable web content, including categories of content, specific web sites, sites with specific keywords, and access to sites requiring https
  • Block access to all websites that are not explicitly approved
  • Access restrictions tailored by user
  • History of websites visited for each user account
  • Blocks inappropriate emails
  • Email activity reports (e.g., websites that were blocked, blocked chats via AntiPredator or keyword triggering, attempts to access encrypted sites)
User Profiles And Custom Parental Controls For Each Child

ContentBarrier allows for individual user profiles with customizable parental control settings for each family member. This allows families to apply restrictions based on the age groups of their children.

App Control

Restrict app usage to only approved apps.

Keystroke Logging

Record keystrokes to monitor instant messages, emails, and more.

Screenshot Monitoring

Periodically takes screenshots of the child’s desktop and saves them for review.

Anti-Predator Chat Monitoring

The Anti-Predator chat monitor feature monitors all standard chat protocols to detect inappropriate content and if it detects anything suspicious it immediately blocks the chat and emails the parent. 

With the Anti-Predator chat monitor you can view the history of recorded chats, including the content of the chat and the ID of the chat partner. Its database of phrases is completely customizable and features five different languages. 

Set Time Limits On Internet Use

ContentBarrier lets parents control and restrict the time of day their children can access the Internet, so they don’t try to sneak screen time late at night.

Time of day restrictions restrict internet access to specific times of the day, specific days of the week, a maximum amount of time per day, or temporarily blocks the user for a set period of time or until you unblock them manually.

Reviews

Reviews for Intego ContentBarrier are largely positive. The anti-predator functions have helped it stand out from competing parental control software. Their support has also been given praise by third-party review sites.

“ContentBarrier is Intego’s parental control software, and I can safely say it’s one of the best around. It’s pretty advanced compared to the built-in Mac parental controls, and it also has a number of features that even Norton and Kaspersky — which have some of the best parental controls — don’t offer. ContentBarrier includes features like keystroke tracking, anti-predator alerts, screenshot recording, and application blocking.”

Katarina Glamoslija, SafetyDetectives.com (2022)

“Perfect Protection for younger children!

This product helps protect your kids in multiple ways and beyond “safe browsing”. It integrates at the operating system level. This means that it works no matter what browser or e-mail or chat client you use…

The program includes standard “filters” for the types of web sites allowed; Gambling, Adult, Shopping, etc…. and also what is allowed in chats (things like “Are your Parents Home?”) The options also include what types of services/programs the user can run. For example, I can say that my teen can chat, but my 10 year old can’t…

One of the benefits of this program is that it has both time of day as well as length of day settings. (Normally you don’t see both in programs like this) Meaning, I can not only restrict my teen from using the computer only from 6AM to 10PM, but I can also combine in “for no more then 3 hours total for the day”. No more wasting time chatting or being on after lights out. Combined with the logging feature, it is really easy to tell if the child was doing homework and legitimately needs more time . (Which the parent can override the settings)”

G. Murray, Amazon (2010)

“Intego ContentBarrier X9 offers 24/7 support from either filling out the contact form or through live chat on the Intego website. Response times are fast, and the staff is very knowledgeable. Further support is available directly from the Intego Twitter page.”

internet-security.bestreviews.net

Support

  • ✅ Email/Help Desk
  • ✅Knowledge Base
  • ❌ Phone Support
  • ✅ Live Chat

Apple’s Native Platform Deployment Options (Apple Business Manager/Apple School Manager)

Overview

iOS, iPadOS, and macOS support multiple forms of content filtering, including restrictions, global HTTP proxy with TLS/SSL inspection, filtered DNS, DNS Proxy, and advanced content filtering.

Businesses can leverage these natively supported internet filtering options to restrict internet access by using Apple Business Manager, integrating with a third-party MDM solution, or developing their own apps through the Apple Developer Program.

Platforms & Deployment Options

  • ✅ macOS
  • ❌ Windows
  • ❌Linux
  • ❌ Chromebook
  • ❌ Android Devices
  • ✅ iOS Devices
  • ✅ iPadOS
  • ❌ tvOS

Pros/Cons

Pros
  • Free*
Cons
  • Requires integration with an MDM solution, Apple Configurator, and/or the Apple Developer Program to take full advantage of its capabilities 

Price

Businesses can use Apple Business Manager completely free of charge. Using Apple Business Manager is highly recommended for any business purchasing Apple devices for their employees. However, it‘s meant to be used together with an MDM solution, which may have an associated cost.

Membership costs for the Apple Developer Program (if you are looking to distribute custom apps to businesses in Apple Business Manager) will need to be considered.  

Features

Web Content Category & URL Filtering

Website restrictions can be configured with Screen Time or with the Web Content Filter payload. Your mobile device management (MDM) solution can also configure website restrictions. 

The setting can be configured to allow all websites, limit adult content or specific websites only, or save usernames and passwords for specific websites:

  • All websites: Web content isn’t filtered.
  • Limit adult content: Limits access to many adult websites automatically.
  • Specific websites only: Limits access to predetermined websites, which can be customized.

In macOS 10.15, or later you can also:

  • Filter data
  • Filter packets
  • Set the filter grade type: firewall or inspector
Global Http Proxy With TLS/SSL Inspection

Apple devices support global HTTP proxy configuration. Global HTTP proxy routes most device web traffic through a specified proxy server or with a setting that’s applied across all Wi-Fi and cellular networks. 

This feature is commonly used by K–12 or businesses for internet content filtering in an organization-owned one-to-one deployment, in which users take their devices home. It allows the devices to be filtered both in school (or at the place of business) and at home. 

VPN/Packet Tunnel

When devices send network traffic through a VPN or packet tunnel network activity can be monitored and filtered. This configuration is similar to devices that are directly connected to a network where traffic between the private network and the internet is monitored and filtered.

DNS Proxy MDM payload

You can configure DNS Proxy settings for users of iOS, iPadOS, and macOS devices enrolled in a mobile device management (MDM) solution. Use the DNS Proxy payload to specify apps that must use DNS proxy network extensions and vendor-specific values. Use of this payload requires an accompanying app that is specified using the app’s bundle identifier.

Network Proxy Configuration

A proxy server acts as an intermediary between a single computer user and the internet so that the network can ensure security, administrative control, and caching service. Use the Proxy MDM payload to configure proxy settings for Mac computers enrolled in a mobile device management (MDM) solution. 

This payload supports configuring proxies for the following protocols:

  • HTTP
  • HTTPS
  • FTP
  • RTSP
  • SOCKS
  • Gopher

Reviews

There are no reviews for this Apple feature.

Support

  • ✅ Email/Help Desk
  • ✅ Knowledge Base
  • ✅ Phone Support
  • ❌ Live Chat

AppleCare for Enterprise offers 24/7 technical support for end users and onsite service for two, three or four years; the pricing for AppleCare for Enterprise is not publicly listed. 

AppleCare for Enterprise is available in volume-based price tiers starting at 200, 1000 and 5000 covered devices. Contact Apple, an Apple Authorized Reseller or an Authorized Carrier Partner to receive a quote for AppleCare for Enterprise.

For more information, see the AppleCare Professional Support page.

The Best DNS Internet Filters For Networks

cybersecurity expert on a laptop ion front of servers

Last Updated: 13 April 2022

DNS filtering is similar to URL filtering in that they both block websites; the key difference is that DNS filtering blocks entire websites based on DNS queries rather than specific URLs. DNS Filtering relies on the Domain Name System (DNS) to block, or allow, content on a specific network. 

DNS is platform and browser agnostic, giving DNS filtering tools the ability to apply web access rules across all devices independent of the OS or browser type. 

DNS filtering will allow you to block undesirable domains for your entire network, however it lacks the ability to block a website while allowing individual web pages within that site.

DNS filtering products work at the network level, making it easy to configure a single policy that applies to all devices that connect to a given network. 

While this is not as customizable as the features provided by an endpoint-based web filter and the policies cannot protect off-network devices without a dedicated software agent, it is an ideal solution for organizations that want to control internet access for guest networks.

Learn More: What’s the Best Way to Block Websites?

WebTitan

See Also: WebTitan Alternatives

Overview

WebTitan is a DNS internet filtering service provider that is suitable for MSPs, internet service providers, and guest networks. It works by routing network internet traffic through its DNS service where the requested websites are then categorized based on WebTitan’s website category database. 

WebTitan offers a cloud-based service that makes setup as simple as logging in, adding your external IP address, installing the WebTitan SSL certificate, and setting up your desired internet use policy before redirecting your DNS to WebTitan 

Platforms & Deployment Options

WebTitan can be deployed via the cloud or on premises as a software or virtual appliance.

As the cloud-based deployment requires no local software installation it is entirely platform agnostic, making it suitable for mixed platform environments.

WebTitan offers businesses a choice of two cloud-based Internet filters – WebTitan Cloud to protect fixed networks, and WebTitan Cloud for WiFi to protect wireless networks and the users connected to them. Both are deployed via a redirection of the business´s DNS server settings.

To ensure that remote workers have the same DNS filtering policy as their in-office counterparts, WebTitan offers a roaming agent known as WebTitan On-the-Go. The roaming client is compatible with Windows, Mac, iOS and Chromebooks.

Pros/Cons

Pros
  • Affordable 
  • Platform agnostic, great for mixed platform environments
  • Multi-tenancy options great for Managed Service Providers
Cons
  • DNS only, forced to block full websites; lacks granular filtering such as blocking a website but allowing specific URLs
  • Minimum license count of 25 Users
  • Internet activity reports provide limited details when compared to a dedicated internet monitoring solution

Price

WebTitan cloud is priced at $532.00 per year for a minimum of 25 users, with discounts available for higher user counts and multi-year contracts. A free 30 day trial is available.

Features

URL Classification & Web Content Filtering

WebTitan’s web category filtering sorts URLs into 53 predefined categories such as social media, news, pornography, gambling etc. It includes a category that blocks known malware, phishing, viruses, ransomware & malicious sites.

Policy Bypass

One pain point of category-based web filters is that websites are occasionally misclassified. To help mitigate the impact of false positives WebTitan offers Cloud Keys that allow you to create exceptions to the general internet policy without having to alter the policy for an individual.

Each Cloud Key can be created for single or multiple uses, controlled by time or date and enabled or disabled by the administrator.

Customisable Block Page

A Block Page or Access Denied Page is the web page that displays when a user attempts to access a website that they are not permitted to view because of their policy settings. In WebTitan you can customize the title, access denied message, and provide additional information.

Flexible Policies

WebTitan’s filtering policies can be customized per IP and per location. You can create allow lists that provide exceptions to the general policy to, for example, block all social media except LinkedIn.

After installing a DNS Proxy and the WebTitan Active Directory Agent (WADA) on your network WebTitan Cloud can also assign custom policies to a user or groups of users.

Application Controls

WebTitan Cloud allows organizations to block access to unwanted applications, such as games and P2P apps.

Internet Usage Reporting

WebTitan offers a few internet usage reports, with metrics such as:

  • The most common website categories requested in your network
  • Web browsing time by Users/Domains/URLs
  • Top Locations/IPs/etc with the most requests
  • Top Domains with the most requests 
  • Blocked requests
  • Top IP addresses with most requests to phishing sites

Reviews

Reviews for WebTitan praise its overall ease of use and support. They are most critical about the complexity of setup for networks that require more than the basic DNS service and the lack of granularity some of the features have.

“Pros: WebTitan, like all TitanHQ products, is immediately ready to use and requires minimal technological effort to ensure the safety of all of your employees. Remote, domestic, and traveling workers can all benefit from the OTG client’s security features. It’s difficult to say what to say. DNS security that covers all bases.

Cons: There is a bit of a delay when importing restricted sites. Likewise, I dislike the WADA agent, but I am ready to accept it in exchange for AD integration.”

Anonymous Verified Reviewer, Capterra (2022)

“Pros: We have used similar products but they kept changing the product and increasing the cost, they would have no customer support and you could not even email them. WebTitan has excellent support and service, they helped us set it up, configure it, and install it. They are super responsive on email their products works for exactly what we want it to do. It was the best solution for us to monitor some end clients without limiting the rest of the network or having something we could not easily access. For us it is the prefect product, something non-IT staff can set up monitor and use daily to limit risks by a completely open internet policy. This was exactly what we needed!

Cons: My only gripe would be that the install for the OTA product is a little tricky to install. Not super hard but an app or something that is easy would have been preferred, so it kind of makes a one man band kind of set up. Of course, we could have installed it on the whole network but that was what we were trying to avoid a complex install that only our network people could really set up and deploy.”

Mark H., Capterra (2021)

“Basic, mid level product.

Pros: Fairly easy to implement as SaaS service, but still needs a service installed that runs on all endpoints.

Cons: It needs the ability to block nefarious sites at a more granular level. Anonymous reporting is too vague and too pervasive.”

Rick P., Capterra (2021)

“Pros: Cloud based management with proxies onsite. Easy to change rules and allow one time access to blocked sites for approved use. Logging is good.

Cons: Remote users, laptops and home users are not protected when off company network. Relying on the proxy servers as dns servers works great when onsite. Has a hard time with Remote Desktop Servers, identifying users… these may be misconfigurations but we have not found an easy way for their WADA to break out RDS users.” – Brian M., Capterra (2020)

Support

  • ✅ Email/Help Desk
  • ✅ Knowledge Base
  • ✅ Phone Support
  • ✅ Live Chat

OpenDNS/Cisco Umbrella

Overview

OpenDNS and Cisco Umbrella are both DNS-based internet filtering services provided by Cisco. OpenDNS provides a basic suite of network filtering features that is best suited for home networks, prosumers, and small businesses. 

Cisco Umbrella is an enterprise product that expands on the features of OpenDNS with options for a Secure web gateway, Cloud access security broker (CASB) features, a cloud-delivered firewall,in-line DLP inspection and blocking, as well as reporting features.

OpenDNS

“OpenDNS is an American company providing Domain Name System (DNS) resolution services—with features such as phishing protection, optional content filtering, and DNS lookup in its DNS servers—and a cloud computing security product suite, Umbrella, designed to protect enterprise customers from malware, botnets, phishing, and targeted online attacks. The OpenDNS Global Network processes an estimated 100 billion DNS queries daily from 85 million users through 25 data centers worldwide.” – Wikipedia

Until June 2014, OpenDNS provided an ad-supported service and a paid advertisement-free service. Once OpenDNS was bought by Cisco in 2015 it split into OpenDNS for consumers and small businesses and Cisco Umbrella for enterprise users.

OpenDNS is a suite of consumer-focused products aimed at making your internet faster, safer, and more reliable. It is best for home or small business users. OpenDNS offers DNS resolution as an alternative to using Internet service providers’ DNS servers or locally installed DNS servers. 

With filtering or pre-configured protection, you can safeguard your family against adult content and more. It’s the easiest way to add parental and content filtering controls to every device in your home network.

Cisco Umbrella

Cisco Umbrella provides protection against threats on the internet such as malware, phishing, and ransomware.

Its SASE architecture combines the functions of network security, including zero-trust network access, cloud access security broker (CASB), secure web gateway (SWG), and firewall as a service (FWaaS) with wide area network (WAN) capabilities to support the secure access needs of organizations.

Platforms & Deployment Options

As OpenDNS and Cisco Umbrella are both DNS-based products their basic DNS functions are entirely platform agnostic. Both include options for endpoint clients that enable more granular control.

OpenDNS

OpenDNS applies filtering settings based on the public IP address of your network. Deploying OpenDNS is usually as simple as making a small configuration change to your external DNS to point it to their nameservers.

The recommended deployment method involves configuring DNS settings to the home router, though there are deployment methods that specifically configure workstations, smart devices, and servers.

The OpenDNS Prosumer client is available for Windows or Mac.

Cisco Umbrella

Cisco Umbrella is deployed through the configuration of an Umbrella virtual appliance (VA). Two VAs are required for high availability. In the case of multiple distant offices connecting to a central Umbrella server, each office requires their own pair of VAs.

Cisco Umbrella’s endpoint clients are compatible with Windows, Mac, Chromebook, iOS, and Android.

Pros/Cons (OpenDNS)

Pros
  • Free versions and inexpensive paid versions
  • Simple to set up
Cons
  • Lacks granularity of policies due to DNS-level blocking; filtering affects all devices on the network equally.
  • Internet activity monitoring is limited to domain-level insights, not specific URLs. OpenDNS Home knows only about the DNS traffic originating from your entire network. It has no way to differentiate between individual devices and users.
  • Cannot block apps such as social media apps and games

Pros/Cons (Cisco Umbrella)

Pros
  • One of the leading tools in the Secure Access Service Edge framework (SASE)
  • Support IT security integrations such as Splunk, PhishMe, and ThreatConnect
  • Threat intelligence backed by Cisco Talos
  • Simple and fast configuration
Cons
  • URL filtering not available for DNS Security tiers
  • Cost prohibitive for anyone that is not a SME

Price

OpenDNS

OpenDNS Home Free is available at no cost. It uses a preconfigured web content filtering database to block specific categories of websites.It includes options such as Family Shield that is preconfigured to block adult content and the classic OpenDNS Home which offers customizable filtering and basic protection.

OpenDNS Prosumer is $20.00 per user, per year (up to 5 users) and uses the Cisco Umbrella dashboard. It protects personal devices on or off-network via Windows or Mac agents. It does not provide network-wide coverage, just coverage for particular Windows and Mac computers. 

The Prosumer version offers:

  • Built-in protection for malicious phishing & malware domains
  • 1 year of internet usage statistics
  • Restrict internet access to only a specific list of allowed domains

OpenDNS Home VIP is $19.95 per user, per year. It is like OpenDNS Home Free but the stats are kept for one year instead of 2 weeks, there are 50 instead of 25 entries for blacklist/whitelist, and there is an optional whitelist-only mode which can be enabled.

OpenDNS Premium DNS uses the Cisco Umbrella dashboard with enhanced stats and logs including real-time activity monitoring, but it does not come with any filtering or blocking. It just shows the categories the domains belong to if the domains are already categorized.

Cisco Umbrella

There are various packages available for Cisco Umbrella, each with their own features and price points. There is also a separate DNS Monitoring Package that provides free, recursive DNS services with real-time reporting and categorization but no internet blocking features.

The main packages are

  • DNS Security Essentials
  • DNS Security Advantage
  • SIG Essentials
  • SIG Advantage

Paid support packages are available, though pricing is not listed on their website. According to WebTitan the Cisco Umbrella DNS pricing in January 2022 is in the region of $2.70 per user per month. CDW lists Cisco Umbrella Insights – 3-Year Subscription License + Gold Support for $84.99.

You can try Umbrella for free for 14 days.

Features (OpenDNS)

Time Limits Controls

OpenDNS includes the ability to enforce schedules to limit time online for the entire web or select websites.

Time of day block allows you to configure content filtering that changes according to the specific time intervals. Time blocks can be set in 15 minute increments. As an example, you can block certain categories from 5 PM to 8 PM and use the ‘All other times’ setting for the rest of the day.

Allow & Block Lists

OpenDNS provides web content filtering at the individual domain level, which enables administrators to use allow and block lists to limit internet access. 

When you manage domains directly, these settings override any specified through category filtering. For example, you can filter the Social Networking category while allowing access to Facebook.

Web Content Category Filtering

OpenDNS provides web content filtering categories that you can apply to your network.  The custom setting allows filtering from over 55 content categories. 

Features (Cisco Umbrella)

Cisco Umbrella’s features are spread throughout their various packages. What features are available are dependent on whether you get DNS Security Essentials, DNS Security Advantage, SIG Essentials, or SIG Advantage.

DNS-Level Internet Activity Monitoring
  • See the domains/subdomains accessed, the categories they belong to, timestamp, and whether or not they were blocked.( It cannot see specific URLs)
  • The DNS Monitoring Package provides free, recursive DNS services with real-time reporting and categorization (DNS Monitoring does not include any enforcement or blocking capabilities.) All internet activity over any port or protocol is logged and categorized by 8 types of security threats, as well as 80+ types of web content. Users can search, filter, and export 14-days of activity. 
  • Proxy and inspect web traffic (incl. decryption of SSL (HTTPS) traffic)
  • Forward external DNS for on-network coverage and off-network devices
  • Real-time activity search, plus reporting API to easily extract key events
Secure Web Gateway

Cisco Umbrella routes risky domain requests to a selective proxy for deeper URL and file inspection. This allows you to effectively protect critical infrastructure without delay or performance impact.

Data Loss Prevention (SIG Only)

Cisco Umbrella data loss prevention (DLP) inspection and blocking capabilities protect sensitive data from being transmitted to unwanted destinations. You can monitor and enforce DLP policies in real-time and inspect data in-line with full SSL inspection.

Malware Protection

The SIG tiers allow you to sandbox suspicious files for further inspection. You can also block files based on signatures from an antivirus engine.

Internet Filtering
  • Create custom block/allow lists of domains
  • Enable web filtering by domain or category (filtering by URL only available in SIG packages)
  • Forward external DNS for on-network coverage and off-network devices
Cloud Access Security Broker (CASB) Functionality

Cisco Umbrella provides visibility into cloud apps used across your organization, giving you the ability to identify potential risks and easily block specified applications.

Cisco Cloudlock is the API-based cloud access security broker (CASB) that helps accelerate use of the cloud. By securing your identities, data, and apps, Cloudlock combats account compromises, breaches, and cloud app ecosystem risks.

Umbrella’s CASB features also include cloud app discovery, risk scoring, blocking or activity controls. You can scan and remove malware from cloud-based file storage apps

Reviews

OpenDNS

“Great for my test lab at home where I play with website development. Not so great in the enterprise. Would probably be a good fit for cash strapped small business.”

Robert Stahl, Spiceworks.com (2016)

“What do you like best?
It was really easy to configure and let the rest do it for itself. I have 2 nephews and they keep using my laptop to watch internet videos and they don’t really know about phishing or suspicious websites. This is the best way to relax and let them navigate freely when I’m not around.

What do you dislike?
The amount of RAM it takes sometimes made me realize it wasn’t a really good choice when my little nephews weren’t visiting me abroad so I uninstalled it when they were back to the country. I’ll use it again when they visit me”

Julián C, G2.com (2019)

“What do you like best?
OpenDNS is super easy to set up and once setup in your router covers all devices connecting to it. It’s very good at filtering inappropriate content like pornography or many other categories that are laid out

What do you dislike?
It’s unfortunate though that If users have administrative access to their internet settings they could bypass the dns lookup setting that keep OpenDNS working.”

Eddie R, G2.com (2018)
Cisco Umbrella

“What do you like best?
1. Easy to configure Network and security profiles.
2. Web filter option for different categories.
3. Easy to configure end devices.
4. Easy to monitor users who visited malicious domains.
5. Option to take reports for the DNS queries.
6. Option to block and allow specific URLs.

What do you dislike?
1. Logs take time to appear in the dashboard.
2. Cost of the subscription is expensive.”

Pinisetty S, G2.com (2021)

“What do you like best?
It’s relatively easy to set up and maintain policies. It’s very effective at controlling access to sites that violate corporate policy or potentially malicious content while being transparent to users. Used in conjunction with AnyConnect VPN, Umbrella also protects off-site users.

What do you dislike?
There’s not much to dislike about Umbrella. It’s not inexpensive, but well worth it for the additional layer of protection it provides.”

Anonymous Verified Reviewer, G2.com (2021)

“What do you like best?
I like the idea of DNS query filtering beyond what’s typically available at no cost. I like the ability to do reporting on the data to get insights not typically available without manually collating DNS lookup data. I also like the idea that if DNS results are returned for malicious websites or services you can point a finger at your vendor and that provides some CYA.

What do you dislike?
I dislike the implementation documentation, the confusing nature of the setup calls, and overall the idea that the sales people don’t really grasp the technical requirements for enterprise rollouts. They just sell sell sell and really don’t take the extra time to learn current architecture, caveats, etc. They solution requires virtual appliances (which they weren’t very helpful designing architecture) and installing agents on the domain controllers (which they also weren’t exactly upfront about). They left me and my team to learn the ins and outs and design the rollout. We also had to enable different audit logging on our domain controllers and they didn’t tell us that either.”

Evan L, G2.com (2018)

Support

OpenDNS
  • ✅ Email/Help Desk
  • ✅ Knowledge Base
  • ❌ Phone Support
  • ❌ Live Chat

Cisco Umbrella

Cisco Umbrella has paid support tiers. Pricing is not publicly available, though they do provide a support packages datasheet with more information.

  • ✅ Email/Help Desk
  • ✅ Knowledge Base
  • ✅ Phone Support (Paid Extra)
  • ✅ Live Chat

Why Filter Internet Access?

This section will briefly cover the benefits of blocking websites. For more information, see our article on the benefits of web filtering for businesses.

  • Blocking Distractions: Block distracting websites such as social media and games sites.
  • Reduce Bandwidth Usage: Block bandwidth hogs such as Twitch and Netflix to improve network speeds and bandwidth availability for work-related activities.
  • Improve Internet Security: Prevent access to high-risk websites such as P2P sites and domains known to host malware
  • Prevent Data Loss: Restrict access to web-based data egress points such as unauthorized cloud storage sites
  • Block Access to Inappropriate Content: Ensure a respectable work or school environment by preventing access to adult content. This aspect of filtering is a critical component of meeting CIPA compliance requirements.
  • Enforce Internet Use Policies: Companies implement acceptable use of the internet policies to ensure that business networks are used safely and appropriately. Web filters are a critical component of enforcing these policies.

Conclusion & More Resources

What is the best internet filter for you depends greatly on your needs. Whether you are a parent looking for parental control apps to limit and monitor your child’s online activity and limit screen time or a business that needs to secure multiple devices against distracting websites and malware, there is a suitable website blocker for you.

Start Blocking Websites Today—Get Your Free Trial of BrowseControl

Need to restrict internet access in your network? In this tutorial you will learn how to block websites using a free trial of BrowseControl, CurrentWare’s web content filtering software.

With BrowseControl you can…

Block websites based on URL, category, domain, or IP address

Schedule unique internet restrictions throughout the day 

Assign custom policies for each group of computers or users,

and enforce internet usage policies, even when devices leave the network

There are 3 ways to block employee internet access with BrowseControl

1) Block access to specific websites with the Block List

2) Restrict internet access to only certain sites with the Allow List 

3) Using the Category Filtering feature you can block access to content categories such as Porn, Virus Infected, or Social Media 

For complete control over internet and application use in your network, you can combine BrowseControl with BrowseReporter, CurrentWare’s internet monitoring software.

All right, let’s get started.

To begin, sign up for a free trial of BrowseControl at CurrentWare.com/Download. After filling out the form you will be provided with the files you need to get started with BrowseControl.

To install BrowseControl, run CurrentWare.exe on the administrator’s computer and follow the installation instructions; this will install the CurrentWare Console and Server. 

After that, deploy the CurrentWare Client Setup file (cwClientSetup.exe) on all of the computers you would like to control. 

From there you can import your Active Directory organizational units or manually create your desired policy groups.

For full installation instructions, please visit our knowledge base at CurrentWare.com/Support. 

Now that you have BrowseControl installed, I’ll show you how to block specific websites based on their URL, domain, or IP address with the URL Filter.

This feature can be used to block your employees from accessing distracting websites like Facebook, TikTok, or Instagram.

First, decide whether you want to control internet access based on users or computers and select the desired mode.

Next, click on the URL Filter then select “Blocked List”

From the drop-down menu, select the group of computers or users that you want to restrict

Enter the URL, domain, or IP address of the websites you want to block to the master URL list, then press the Enter key or click “Add”. 

BrowseControl will apply a wildcard to the URL, ensuring that any paths within the domain will be blocked as well.

In the master URL list, select the websites you want to block for the chosen group, then click “Add to Blocked List”.

If you would like to add the selected websites to the block list of multiple groups, you can press the drop-down arrow and select “add to multiple groups”, select the desired groups, then click “add to blocked list”

If you have a large number of websites you would like to block, you can also use the import feature to import an existing list.

Finally, click “Apply to Clients”.

That’s it! You have now blocked your employees, students, or patrons from accessing those specific websites. 

Next, I’ll show you how to restrict internet access to only certain sites.

This feature is ideal if you want to prevent your employees, students, or patrons from accessing websites that are not explicitly allowed by your organization.

The process is identical to how you would block a website, except this time you will set the internet to “off” and add the websites you would like to allow to the Allow List.

With this method, your users will only be able to access the exact websites that have been approved by your company.

Here are the full instructions.

First, decide whether you want to control internet access based on users or computers and select the desired mode.

Next, click on the URL Filter, then ensure that “Allowed List” is selected

From the drop-down menu, select the group of computers or users that you want to restrict

Next, set the internet to “Off”. This will ensure that only the websites that are added to the allowed list can be accessed.

Enter the URL, domain, or IP address of the website you want to allow to the master URL list, then press the Enter key or click “Add”. BrowseControl will apply a wildcard to the URL, ensuring that any paths within the domain will be allowed as well.

In the master URL list, select the websites you want to allow for the chosen group, then click “Add to Allowed List”

If you would like to add the selected websites to the Allowed list of multiple groups, you can press the drop-down arrow and select “Add to Multiple Groups”, select the desired groups, then click “Add to Allowed list”

If you have a large number of websites you would like to allow, you can also use the import feature to import an existing list.

Finally, click “Apply to Clients”.

Next, I’ll show you how to block websites based on content categories such as Porn, Virus Infected, and Social Media 

With BrowseControl’s category filtering feature you can block billions of websites across over 100 URL categories. More than 10,000 new domains are added each day, making it simple to restrict internet access even as new sites emerge. 

Here’s how:

First, decide whether you want to control internet access based on users or computers, then select the desired mode.

Next, click on “Category Filtering”

From the drop-down menu, select the group of computers or users that you want to restrict

Select the web content categories you would like to block, then click “Add to Blocked List”

Finally, click “Apply to Clients”.

That’s it! 

The Allow List can also be used in tandem with the Category Filtering feature to allow websites that would otherwise be blocked based on their content category. 

For example, you could use the Category Filtering feature to block Social Media while still allowing access to LinkedIn.

Now that you’ve seen the 3 key ways you can block a website with BrowseControl, I’d like to show you how to restrict internet access at certain times.

With BrowseControl’s Internet Scheduler you can schedule custom block or allow lists throughout the day. 

This feature will bring some flexibility to your internet restriction policies; in this example, we will allow our employees to browse the internet during lunchtime.

Here’s how to use the internet scheduler

First, decide whether you want to control internet access based on users or computers and select the desired mode.

Next, click on “internet scheduler”

From the drop-down menu, select the group of computers or users that you want to restrict

Next, click “New Schedule”

Set the start and end time of the schedule. Then, select the schedule type.

Internet On will allow internet access to all websites that are not on the URL Block List

Custom allowed list will only allow access to specific websites.

Custom blocked list will block access to a specific list of websites and allow access to the rest of the internet.

Custom Category blocked list will block specific categories and allow access to the rest of the internet.

Next, set your desired schedule frequency.

Daily will enable the schedule every day during the specified time period.

Weekly will enable the schedule only on specific days of the week.

Monthly will enable the schedule only on specific months.

Next, click “Add Schedule”.

If you selected one of the custom block or allow list options, you can click the link provided under the “schedule type” column to set the websites or categories that you would like on the list.

And finally, click “Enable Scheduler” if it is not already enabled

That’s it for today. If you’re ready to start blocking websites you can get a free trial of BrowseControl at CurrentWare.com/Download. 

If you have any questions during your evaluation our support team is available to help you over a phone call, live chat, or email.

See you next time!

Are you a business looking for a cost-effective website blocker solution for blocking sites for your remote and in-office employees? Get started today with a free trial of BrowseControl, CurrentWare’s internet filtering software.

For further control over internet use you can combine BrowseControl with BrowseReporter, CurrentWare’s computer usage monitoring software for tracking time spent browsing the internet and using Windows apps. Both modules operate from the same central console, making managing internet use for your users simple and convenient.

BrowseControl’s Key Features

  • Website & App Blocking: Block apps, IP addresses, domains, URLs, and URL keywords
  • Web Category Filtering: BrowseControl’s category filtering database provides you with a convenient way to block millions of websites across over 100 URL categories. Easily block users from accessing social media, porn, games, virus-infected websites, and more!
  • Time Controls: Control internet access based on time limits and schedule unique restrictions
  • Granular Customization: Set unique policies for all your devices and users based on groups
  • Central Management: Configure policies for your entire workforce from a central console

Want to learn about more features? Click the “Learn More” button below for a full list of BrowseControl’s web control features.

Further Reading

Sai Kit Chu
Sai Kit Chu
Sai Kit Chu is a Product Manager with CurrentWare. He enjoys helping businesses improve their employee productivity & data loss prevention efforts through the deployment of the CurrentWare solutions.

Pin It on Pinterest