LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-12-2009, 04:17 PM   #1
pcchicks
LQ Newbie
 
Registered: Sep 2009
Posts: 2

Rep: Reputation: 0
Limit Internet access to specific directories


Does any one know how to limit Internet access into a Linux server to specific folders? I would still like users to be able to VPN in then use VNC, but not be able to access specific protected directories.
 
Old 09-12-2009, 04:38 PM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,634

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by pcchicks View Post
Does any one know how to limit Internet access into a Linux server to specific folders? I would still like users to be able to VPN in then use VNC, but not be able to access specific protected directories.
Yes, but you're going to have to provide some details, before anyone can help you.

What do you mean by "Internet access"? Lots of different protocols, and without knowing how folks are getting to your system, we can't really tell you how to set anything up. Also, if they're getting a VNC connection, it's just like they're sitting at a console....they can log in and get a desktop, so unless they're limited at their desks at the office, they're not going to be over VPN/VNC, either....

What is the need? What are you trying to accomplish? And what version/distro of Linux are you using?
 
Old 09-12-2009, 08:50 PM   #3
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Rep: Reputation: 55
If you mean http access use a .htaccess file, if you mean ssh access, use group permissions.
 
Old 09-13-2009, 09:05 AM   #4
pcchicks
LQ Newbie
 
Registered: Sep 2009
Posts: 2

Original Poster
Rep: Reputation: 0
Red Hat Linux 5 server

I have users VPN and authenticate to a Windows server. Then they VNC to the Linux server that is not setup as a domain. I am trying to prevent outside the office access to specific protected files and directories that should only be accessed from within the office on the Linux server.
 
Old 09-13-2009, 12:09 PM   #5
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,634

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by pcchicks View Post
I have users VPN and authenticate to a Windows server. Then they VNC to the Linux server that is not setup as a domain. I am trying to prevent outside the office access to specific protected files and directories that should only be accessed from within the office on the Linux server.
Nothing you can do, based on what you're describing.

First, if they VPN into a Windows server that's on your network, they're INTERNAL at that point, when they initiate the VNC connection. And again, if they're VNC'ing over, it's just like they're sitting at a console.

You can implement a groups-based solution, like abefroman suggested, and let them connect via SSH, instead of VNC, or do a web-based solution, which could be be locked down to accept connections from only one address, and severely limit what they can access from the web page's code.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
limit specific proces to a specific user Tux-Slack Linux - Software 3 02-23-2007 11:38 PM
blocking specific websites, but allowing internet access poiuytrewq Linux - General 6 08-31-2006 11:45 PM
How do I limit Internet access? jmelgin Linux - Newbie 12 07-06-2005 04:07 PM
Limit internet access for certain hosts during certain time i16978 Linux - Newbie 2 05-05-2005 12:19 AM
How to limit telnet access to a specific directory based on logon? Saeven Linux - Networking 3 10-20-2002 05:17 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:39 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration