* SMB auth and Iptables...
@ 2004-07-29 20:51 Gustavo Castro Puig
2004-07-30 7:20 ` Eric Leblond
0 siblings, 1 reply; 3+ messages in thread
From: Gustavo Castro Puig @ 2004-07-29 20:51 UTC (permalink / raw)
To: netfilter
[-- Attachment #1: Type: text/plain, Size: 674 bytes --]
Hi, guys:
One customer asked me about the possibility of install in an iptables based firewall some sort of solution (perhaps a proxy) it could add/delete rules based on users login into a SMB(Samba/NT) server. He want to grant or deny access to Internet (TCP/IP) based on authenticated users, not the IP or MAC. It's not a bad idea, but I don't know if it even exists... I've googled and found nothing about this kind of solution. Anyway, I told him I could check it out, and... here I am. :-)
Do you have any idea about a solution like this using iptables and "something" else?
Any info will be highly appreciated.
Thanks!
Cheers,
Gustavo.
[-- Attachment #2: Type: text/html, Size: 1492 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: SMB auth and Iptables...
2004-07-29 20:51 SMB auth and Iptables Gustavo Castro Puig
@ 2004-07-30 7:20 ` Eric Leblond
0 siblings, 0 replies; 3+ messages in thread
From: Eric Leblond @ 2004-07-30 7:20 UTC (permalink / raw)
To: Gustavo Castro Puig; +Cc: netfilter
[-- Attachment #1: Type: text/plain, Size: 1025 bytes --]
You could use NuFW : http://www.nufw.org to build an authenticating
firewall. There's no direct interaction with samba but if users are
stored in ldap it should be possible to have products work together.
On Thu, 2004-07-29 at 22:51, Gustavo Castro Puig wrote:
> Hi, guys:
>
> One customer asked me about the possibility of install in an
> iptables based firewall some sort of solution (perhaps a proxy) it
> could add/delete rules based on users login into a SMB(Samba/NT)
> server. He want to grant or deny access to Internet (TCP/IP) based
> on authenticated users, not the IP or MAC. It's not a bad idea, but I
> don't know if it even exists... I've googled and found nothing about
> this kind of solution. Anyway, I told him I could check it out, and...
> here I am. :-)
> Do you have any idea about a solution like this using iptables and
> "something" else?
> Any info will be highly appreciated.
> Thanks!
>
> Cheers,
> Gustavo.
--
Eric Leblond <eric@inl.fr>
INL
[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
* RE: SMB auth and Iptables...
@ 2004-07-30 0:20 Steve Wakelin
0 siblings, 0 replies; 3+ messages in thread
From: Steve Wakelin @ 2004-07-30 0:20 UTC (permalink / raw)
To: Gustavo Castro Puig, netfilter
[-- Attachment #1: Type: text/plain, Size: 1026 bytes --]
Squid with NTLM authentication will provide this functionality
-----Original Message-----
From: netfilter-admin@lists.netfilter.org
[mailto:netfilter-admin@lists.netfilter.org] On Behalf Of Gustavo Castro
Puig
Sent: 29 July 2004 21:51
To: netfilter@lists.netfilter.org
Subject: SMB auth and Iptables...
Hi, guys:
One customer asked me about the possibility of install in an
iptables based firewall some sort of solution (perhaps a proxy) it could
add/delete rules based on users login into a SMB(Samba/NT) server. He
want to grant or deny access to Internet (TCP/IP) based on authenticated
users, not the IP or MAC. It's not a bad idea, but I don't know if it
even exists... I've googled and found nothing about this kind of
solution. Anyway, I told him I could check it out, and... here I am. :-)
Do you have any idea about a solution like this using iptables and
"something" else?
Any info will be highly appreciated.
Thanks!
Cheers,
Gustavo.
[-- Attachment #2: Type: text/html, Size: 4339 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2004-07-30 7:20 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-07-29 20:51 SMB auth and Iptables Gustavo Castro Puig
2004-07-30 7:20 ` Eric Leblond
-- strict thread matches above, loose matches on Subject: below --
2004-07-30 0:20 Steve Wakelin
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.