Networking Forums

Networking Forums > Computer Networking > Linux Networking > Restrict internet access to diskless workstations.

Reply
Thread Tools Display Modes

Restrict internet access to diskless workstations.

 
 
maddman
Guest
Posts: n/a

 
      08-14-2003, 06:03 PM
I'm setting up a group of diskless workstations for my company to be
used as information terminals. Let me describe what my setup is like.

- I'm running Mandrake 9.1, with Mozilla and OpenOffice to view web
pages/documents.
- I set up the package from the Linux Terminal Server Project
(http://www.ltsp.org) for the workstations. After a bit of tweaking
and getting all the correct services running (NFS, tftp, etc) this is
working fine.
- The stations will be on a private 10.x.x.x network, with the server
having two NICs to interface to the full class C network. This is so
the stations can access our intranet server (currently on another
machine) as well as the internet.

Here's the rub. We need the terminals to be able to reach only
certain web sites, such as the corporate web site. I'm trying to set
up a system to implement this. Currently, they have full access to
the internet.

I tried to set up hosts.allow and hosts.deny by listing ALL: ALL
EXCEPT 10.x.x. in deny and the domains/IPs that I wanted to access in
allow. But this doesn't seem to work. I can still get out to google
or wherever I'd like to go.

Any help would be greatly appreciated.

madd
 
Reply With Quote
 
 
 
 
tuiflmgbl@gxffze.com.oa
Guest
Posts: n/a

 
      08-14-2003, 06:33 PM
|I tried to set up hosts.allow and hosts.deny by listing ALL: ALL
|EXCEPT 10.x.x. in deny and the domains/IPs that I wanted to access in
|allow. But this doesn't seem to work. I can still get out to google
|or wherever I'd like to go.

Firstly realise that the browser processes are running on the server,
not on the diskless clients. The diskless clients are only the display
and input devices for the browsers.

So you need to restrict by user account on the server. If you are just
running the terminals in locked down public mode, a standard LTSP
recommendation is to pair up each terminal with an account name and lock
that account to run only on that terminal. The password can then be
public, say same as the terminal name. Then use squid rules to grant
access only to the sites you want. If the terminals are not locked down,
then you have to get the users to authenticate against squid.

Check out the LTSP forums where you'll get good advice.
--

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
DHCP workstations can't access internet Static can Mick Windows Networking 2 01-29-2008 03:05 PM
Restrict Internet Access on DGL-4300 Dave Network Routers 1 08-05-2007 03:50 PM
Rep. Pete Sessions from Texas trying to restrict your internet access ? nationally? ed Wireless Internet 1 07-25-2005 08:13 AM
XP Workstations dont have Internet Access? Peter L Windows Networking 2 06-23-2005 07:01 AM
stop/ restrict internet access Dale Home Networking 2 04-06-2005 04:52 PM



1 2 3 4 5 6 7 8 9 10 11