LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 10-04-2012, 01:02 PM   #1
wierdbeard65
Member
 
Registered: Feb 2011
Posts: 32

Rep: Reputation: 1
Question Dans Guardian authentication


Hi,

First up, if this is the wrong forum, please advise!

Ok, I have a home network that the whole family uses. I have a variety of clients from Winoze to iPads to PS3 to XBOX. I also have a linux (Ubuntu 12.04) based server as my firewall.

I want to put some content filtering in to place to protect the internet from my children (or should that be the other way around?) and plan to go for a Squid / Dans Guardian system.

So far, so good. I want transparent proxying in place (some of the devices also get used elsewhere and I don't want to have to turn on and off a manual proxy) which I can (relatively) easily do.

Now for the difficult part, I don't want to have to authenticate each time someone hits the 'net, but IF a website gets blocked, I'd like a link on the blocking page that allows a user to log in and (if appropriate) bypass the filter. When this happens though, I want to make sure it's logged.

All the helpfiles I have seen suggest that:
  1. I need to use Ident as I am transparent proxying
  2. I have to either authenticate or not, I can't ONLY authenticate if a bypass is requested.

Anyone have any thoughts?

Thanks!
 
Old 10-10-2012, 12:55 PM   #2
crabboy
Senior Member
 
Registered: Feb 2001
Location: Atlanta, GA
Distribution: Slackware
Posts: 1,821

Rep: Reputation: 121Reputation: 121
I went down this road probably a year or more ago and got a similar setup working. I used the Dansguardian plugin for IPCop which made it quite easy to setup and configure. I had initially used the transparent proxy but changed it to a normal proxy after having problems and then reading info around that browsers work better when they are aware there is a proxy. So I switched to 8080 and then blocked access to 80.

This didn't go over too well with devices that did not have proxy support, mainly the directv receivers. I also ran into trouble allowing overrides for restricted content. This involves creating logins for the proxy but the ipod devices did not support the security model (don't recall what it was exactly), so I could not use that. Without this, I was adding exceptions every day to the site list, mainly the reality sites my wife chooses to visit. Also, many of the ipod app game servers show up on the restrict list as well. Some of the iphone/ipod apps are not written correctly to use the proxy server either, they flat out don't work even if the proxy is configured in the iPhone.

The content filter is quite nice, it does a good job of blocking based on black, grey and site content, but I had too much trouble allowing exceptions. I've since opened port 80 back up, but keep the kids laptops configured to use the proxy. One day I'll get back to looking at this again.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Ubuntu on Dell Dimension 4500, Dans Guardian, remote access, installation afullmetalwar Linux - Software 2 05-25-2010 11:01 PM
Trying to get a quick n dirty Dans Guardian/Squid install for client mattp Linux - Software 48 01-06-2006 11:46 AM
dans guardian on slackware 10.0 paul_mat Slackware 2 03-20-2005 11:04 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:25 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration