    Blocking any requests not matching defined AD groups


      Dear All,


      We have two MWG's and we are dividing our users based on two AD groups which are 'MWG1 and MWG2', but I noticed if a user is not in MWG1 and MWG2, he is able to browse internet from any of the gateway. I want to have a rule which should check that if a user is not found in any of above AD group, should block him with a message meaningful, should not allow him to browse.


      Please advice how we can do this. See attached screen shot how we are controlling two groups.