Old 09-13-2010, 12:56 AM   #1 (permalink)
Untangler
 
Join Date: May 2010
Posts: 66
BigKnot is on a distinguished road
Default Filter by computer name

In AD i can arrange users as well as computer objects into groups. Will this transfer to a working situation in UT? What i'm looking for to achieve is something like this:

- User A may do everything
- Computer B may not use FTP (member of group "noFTP")

When User A is using Computer B, he will not be able to use FTP. When he uses any other Computer he can use FTP.

Or make it work the other way around: no user may use FTP, but only when they are using a Computer which is a member of the group "FTPallowed" they can use FTP.

I would try this myself, but will have to make my SBS 2003 server single homed before i am able to try these examples
BigKnot is offline  
Old 09-13-2010, 01:06 AM   #2 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

With the AD connector, you can link policy manager rules to use name, and change the security policy based on user name.

To control a computer, you need to define a DHCP reservation, or give the machine you want to control a static address.

Once those two things are in place, you can define whatever control you want.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 09-13-2010, 03:01 AM   #3 (permalink)
Untangler
 
Join Date: May 2010
Posts: 66
BigKnot is on a distinguished road
Default

OK, so i understand that the use of computer object in AD groups isn't going to work. Using DHCP reservations as a workaround is no problem however.

From your answer i'm also doubting if AD groups are supported at all?
I would like to manage access by AD groups (like you can do in ISA) and have groups like "noInternet", "restricedInternet", "fullAccess" in which i can place users. Is this also a no-go and will i have to resort to using usernames synced from AD in UT to achieve this?

Thanks!
BigKnot is offline  
Old 09-13-2010, 03:26 AM   #4 (permalink)
Untangler
 
Join Date: Mar 2010
Posts: 60
WaLshy11 is on a distinguished road
Default

Quote:
Originally Posted by BigKnot View Post
OK, so i understand that the use of computer object in AD groups isn't going to work. Using DHCP reservations as a workaround is no problem however.

From your answer i'm also doubting if AD groups are supported at all?
I would like to manage access by AD groups (like you can do in ISA) and have groups like "noInternet", "restricedInternet", "fullAccess" in which i can place users. Is this also a no-go and will i have to resort to using usernames synced from AD in UT to achieve this?

Thanks!
AD groups do work in untangle
WaLshy11 is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 04:38 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2