LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-11-2003, 03:05 AM   #1
qmesbah
LQ Newbie
 
Registered: Sep 2003
Location: BDESH
Posts: 3

Rep: Reputation: 0
Unhappy how to restrict web browsing in the local lan


i have 2 interface in my server local (192.168.0.1) & internet (Ethernet with real IP). services in the server are proxy, dns, web, mail. using ipchain as firewall. any one can help me to solve these problem -

1. how can i restrict some of my local user only from web browsing, but he will be able to send and receive mail.

2. how can i restrict some of my local user to send external mail but shloud be able to send internally and receive both internal nad external mail, i use sendmail.

Last edited by qmesbah; 09-11-2003 at 03:07 AM.
 
Old 09-11-2003, 06:23 AM   #2
phoeniXflame
Member
 
Registered: Feb 2003
Location: Somewhere, UK
Distribution: Slack, OpenBSD, Debian, SuSE
Posts: 189

Rep: Reputation: 30
Firstly I'd recommend upgrading your kernel as Iptables are now the prefered method of filtering, secondly, just write 2 rules to block incomming packets to your blocked users ip address with a source port of 80 (and 8080 to stop proxys)
 
Old 09-12-2003, 11:12 PM   #3
qmesbah
LQ Newbie
 
Registered: Sep 2003
Location: BDESH
Posts: 3

Original Poster
Rep: Reputation: 0
thanks phoeniXflame
 
Old 09-13-2003, 06:23 AM   #4
ppuru
Senior Member
 
Registered: Mar 2003
Location: Beautiful BC
Distribution: RedHat & clones, Slackware, SuSE, OpenBSD
Posts: 1,791

Rep: Reputation: 50
qmesbah-moshai

What flavour and version of liGNUx do you use?

iptables is currently preferred over ipchains.

if you are using kernel 2.4, you can use iptables.

You had mentioned proxy in your post. I assume you are using SQUID. You can control web browsing using acls in squid.

Last edited by ppuru; 09-13-2003 at 06:24 AM.
 
Old 09-14-2003, 12:15 AM   #5
qmesbah
LQ Newbie
 
Registered: Sep 2003
Location: BDESH
Posts: 3

Original Poster
Rep: Reputation: 0
thanks ppuru.
yeah 2.4 & squid.
i got the solution of my first question.
can any one help me to solve the second one.
 
Old 09-16-2003, 07:59 AM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
2. how can i restrict some of my local user to send external mail but shloud be able to send internally and receive both internal nad external mail, i use sendmail.
Controlled relaying, I guess. Search LQ and Sendmail.org for posts/docs on relaying. After you've read those, adjust your /etc/mail config files, try, test, and post if any errors/questions occur.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Exim, restrict sending from ourdomain.com to local subnet humbletech99 Linux - Security 4 11-25-2005 04:07 AM
Restrict Local logon, but allow network Dogface1SG Linux - Networking 1 11-19-2003 03:35 PM
file transfer over ssh restrict directory browsing niall0s Linux - General 11 09-11-2003 02:50 PM
Restrict Printing on Local Network? franticbob Linux - Networking 3 08-01-2003 03:06 AM
cannot view web page from local lan Tigger Linux - Networking 4 05-31-2003 01:03 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration