LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-19-2012, 02:45 AM   #1
swastikmohangupta
LQ Newbie
 
Registered: Apr 2011
Posts: 3

Rep: Reputation: 0
Blocking other user to access network resources


Hi This is swastik

I want that only my domain members will be able to use network resource as Internet.
Other User will not be able to access any services through my domain.

Someone says me that this will be through LDAP. I dont have any idea how to do it.
It is very required for me to do that in my office today.
Plz help me .
Regards:-
--------------
swastik
swastikmohangupta@gmail.com
 
Old 03-19-2012, 02:49 AM   #2
Skaperen
Senior Member
 
Registered: May 2009
Location: center of singularity
Distribution: Xubuntu, Ubuntu, Slackware, Amazon Linux, OpenBSD, LFS (on Sparc_32 and i386)
Posts: 2,681
Blog Entries: 31

Rep: Reputation: 176Reputation: 176
What kind of use do you mean by "access any services through my domain" ?

Prevent users from logging in by not giving password. But if these are users you need to allow shell login, but still prevent them from accessing the internet, that's much harder.

It is too unclear what you mean by these resources. Since different things may need different methods to control access, there isn't a good way to answer this until we know more.
 
Old 03-20-2012, 12:44 AM   #3
swastikmohangupta
LQ Newbie
 
Registered: Apr 2011
Posts: 3

Original Poster
Rep: Reputation: 0
Blocking Unauthorized user from domain access

i'll brief what exactly i am having:-

1. There is a central domain controller over windows server 2008 for 15 locations.
2. There is a central DHCP server for 15 locations over which 15 different ip pools have been defined for the respective location.

Now,i am looking for some solution with which i can restrict any unauthorized user(which is not in the list of users on domain controller)..

Searching over the internet somewhere i found that something i have to work with LDAP.

Kindly Suggest

Regards:-
------------------
swastikmohangupta@gmail.com
 
Old 03-20-2012, 02:41 AM   #4
Lexus45
Member
 
Registered: Jan 2010
Distribution: Debian, Centos, Ubuntu, Slackware
Posts: 361
Blog Entries: 3

Rep: Reputation: 48
One of possible ways to solve the problem is configuring a Squid proxy server to authenticate off Active Directory.
http://wiki.squid-cache.org/ConfigEx...ctiveDirectory

Another way (not so nice) is to create a separate file/database (independent of domain controller) and it will authorize users. It may have the same login/password pairs as the domain's are. But if your domain security policy is to change passwords every N days, this scheme will be not so elegant.
You may configure MySQL authentication http://wiki.squid-cache.org/ConfigEx...enticate/Mysql
or NSCA authentcation (login:encrypted_password file) (no link, Google please)

Last edited by Lexus45; 03-20-2012 at 02:50 AM.
 
Old 03-30-2012, 05:13 AM   #5
swastikmohangupta
LQ Newbie
 
Registered: Apr 2011
Posts: 3

Original Poster
Rep: Reputation: 0
Only domain members should be able to access Internet

http://wiki.squid-cache.org/ConfigEx...ctiveDirectory

I tried to do this by above link.
In Authentication options of above link there are below methods.
Negotiate/Kerberos, Negotiate/NTLM, NTLM and basic authentication
I am unable to think which method is better.
Plz help me do this by giving step by step method through text or video link

Regards:-
--------------------
swastikmohangupta@gmail.com
 
Old 03-30-2012, 08:17 AM   #6
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Quote:
Originally Posted by swastikmohangupta View Post
In Authentication options of above link there are below methods.
Negotiate/Kerberos, Negotiate/NTLM, NTLM and basic authentication
I am unable to think which method is better.
Of the methods listed, Kerberos would be the most secure, also the most complex. Samba with WinBind (Windows Authentication) would be second, followed by basic authentication. The decision should be based upon your needs, as well as whether or not you already use Kerberos as part of your Windows Domain (you probably do).
Quote:
Plz help me do this by giving step by step method through text or video link
The short answer you will likely receive to this request is: no. You need to do your own searching for instructions on how to accomplish this task. In fact, the link you provided looks pretty good to me as far as a step by step set of instructions. If there are parts of this process that you don't understand, then you need to read, research and learn the missing pieces. Trying to just implement a service of this nature with said understanding will lead to failure or a terribly insecure system. It doesn't matter how badly you believe you need it RIGHT NOW, you must develop the understanding of what you are attempting to do when it comes to centralized authentication systems.
 
1 members found this post helpful.
Old 04-02-2012, 01:05 AM   #7
elfenlied
Member
 
Registered: Dec 2004
Posts: 83

Rep: Reputation: 8
Seeing as you have centralised your DHCP you could make it so that only known devices (mac addresses) are given a lease, although if someone really wants to get on your network they can but this is probably going to be the case regardless.

Also not to point out the obvious but this is a "linux" forum and no where have you stated you are actually using any type of linux so perhaps asking the same question in a Microsoft based forum might yield some more responses.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
I cannot access network resources from my switch in my office and there are no lights Wairaka Linux - Newbie 1 03-18-2008 05:46 PM
Blocking Specific Programs from Network Access? Trip in VA Linux - Newbie 23 08-06-2006 02:47 PM
cannot access network resources outside my gateway symo0009 Linux - Networking 8 12-22-2005 12:35 AM
Remote Access to Home Network Resources Notwerk Linux - Networking 3 05-02-2005 01:21 AM
blocking web access for dial-up user kdemaree Linux - Security 2 12-09-2003 10:38 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:37 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration