Results 1 to 3 of 3
  1. #1
    Untangler
    Join Date
    Jul 2011
    Posts
    74

    Default Block all access for a specific user - Part II

    So...my previous post asking about this, then finding the answer is no longer valid.

    My rule has simply stopped working, PCs logged in under the specified username can access other stuff.

    I made no changes to the box before the rule stopped working.

    My rule looks like this:

    Directory Connector: Username is <username>
    and
    Destination Address is not <IP address of remote server>

    I've rebooted the UT box, restarted Application Control, but no luck.

    Any thoughts? Or any other way of making a rule like this?

  2. #2
    Untangle Junkie dmorris's Avatar
    Join Date
    Nov 2006
    Location
    San Mateo, CA
    Posts
    11,691

    Default

    http://wiki.untangle.com/index.php/A..._Control#Rules

    Application Control rules are only run after the classification of a session is complete by the classification engine.
    Seeing as you're matching on Username and Destination address (of which neither will change by Application Control classification) you might as well use firewall which will block the session immediately.

    Create that rule in firewall, set it to block, verify that you see the username in the status tab in directory connector status, and then try to create a session from that server. That rule should block all sessions except traffic to the specified remote server.
    Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

  3. #3
    Untangler
    Join Date
    Jul 2011
    Posts
    74

    Default

    Thanks! I'll give that a shot.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2