Networking Forums

Networking Forums > Computer Networking > Linux Networking > Firewalling at the domain users level instead of network level

Reply
Thread Tools Display Modes

Firewalling at the domain users level instead of network level

 
 
Santos
Guest
Posts: n/a

 
      07-18-2004, 06:52 AM
Hi all.


I'm implementing a "Windows clients, Linux servers" kind of network.
Some users may login at different machines, therefore, ip level is not
enough. I wonder if it's possible to control the access at the "domain
users" level instead of network or ip level. I could implement some
proxies, but each client machine had to be configured and that would
mean extra work. IPtables can filter at the user level, but only with
local users. Is there a way to configure iptables and kerberos working
together or something like that? Is this doable with PAM? I have read
that SAMBA authenticated gateway HOWTO, but it doesn't look very
reliable. Well, so basically what i want, is a firewall similar to a ISA
Server firewall

Any ideas about this would be apreciated, thanks in advance.


Santos


 
Reply With Quote
 
 
 
 
Raqueeb Hassan
Guest
Posts: n/a

 
      07-18-2004, 02:16 PM
First, you want a linux version of ISA server. Well, the domain
concept of windows is kind of logical ... so, you might have to get
down to ip level filtering. You can use squid and iptables for that.
You can run dhcpd but associate that with MAC , so the ip remains
same. use these ip ranges or individual ips in squid access control
list and iptables.

Someone else might help you with samba kind of solution.


hth

--
raqueeb hassan
kinshasa, drc
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
security level of wireless network indianbillgates Wireless Networks 0 12-14-2005 03:35 AM
[OT a bit] Lower level domain names Frank Stacey Broadband 3 09-02-2005 05:20 PM
network actual bitrate (application level, tcp packet level) nirnimesh@gmail.com Linux Networking 1 01-24-2005 11:24 PM
Issue with shared folders on domain level. Uranium Windows Networking 0 02-11-2004 04:39 PM
setting user level access on me/xp network ED Windows Networking 1 12-14-2003 01:18 AM



1 2 3 4 5 6 7 8 9 10 11