Self-Service Security: Prevent Users from changing the URL to access internal portal.
We have created an ESS portal for external access by our employees, i.e. SELFSERV. This is limited to only the components that have been registered to the Portal for ESS functionality only. However, via URL manipulation, a User can get access to any internal ESS components that the user has security granted via internal portal, i.e. EMPLOYEE.
Is there a way within PeopleTools to prevent them from changing the URL to access the other portal, therefore restricting users to a limited portal while accessing the system externally?
If not, what other options are there, i.e. firewall, third-party software?