LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 12-15-2002, 06:06 AM   #1
aqoliveira
Member
 
Registered: Dec 2001
Location: Portugal
Distribution: /Red Hat/Fedora/Solaris
Posts: 622

Rep: Reputation: 30
Unhappy HOW to - Group ACL


Hi There

I'm looking for software that can do the following.

I have squid with squidGuard running and it's working correctly. I have for example 3 groups with diffrent access to the internet which I can block and creat seperate acls for each group but the problem is that the workstations are not configured with a fix IP. Squid and squidGuard only allows you to configure with an IP or range of IP's.

I was wondering if there is any software that can work with squid or any other independant software (firewall) so that I can set acls for groups of people.

I have also taken a look at Dan's Guardian and IPtables with no success.

Thanking everyone for there input
Tony
 
Old 12-16-2002, 06:00 AM   #2
jdii1215
Member
 
Registered: Aug 2002
Location: SW Coast of Florida, USA-- in fact, ground zero for Charley is where my town is
Distribution: Mandrake 10 Community, SuSE 9+
Posts: 167

Rep: Reputation: 30
Essentially, unless you have semi-fixed IPs you will need to use something like a SSL for security, or see if you can find a way to implement SSL Plus CHAP, unle YOU control the DJCP handouts and can look at something on each machine for a validation of machine ID.

The approach of allowing a TCP port to connect could also be done, but finding an unregistered port could be fun. I would avoid a UDP port, though, and block the UDP equivalent of the TCP port used in this case.

Chatting\IM, for instance, uses ports plus authentication. Each app has its own ports and then the portal servers do the port conversions to existing network ports and pass through the users' IDs. A variation on this might be doable although securing it is complex. Thus a group accees could be a ceratin group ID coming in on a certain TCP port. Part of security is having an unknown-to-public set of individualized requirements that cannot be bypassed.

iana.org has port registration numbers but the printout I did a month ago was 162 pages long.

John.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
what's the difference between main group and other group? hongxing Linux - Software 1 11-14-2005 06:40 AM
well, there's info written inside /etc/group. accidentally del /etc/group in RedHat9 karmakid Red Hat 1 07-27-2005 10:27 PM
/etc/group - the group users empty Artanicus Linux - General 2 02-22-2005 04:25 AM
Group Admin, Group Root, or God over Group crickett Linux - General 5 07-12-2004 04:01 PM
[alert] (22) Invalid argument : setgid : unable to set group id to Group 4294967295 Niraj Linux - Networking 1 12-13-2001 06:58 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 03:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration