Old 11-17-2011, 08:27 AM   #1 (permalink)
Untangle Ninja
 
Mathiau's Avatar
 
Join Date: Feb 2008
Location: Costa Frickn' Rica
Posts: 1,467
Mathiau is on a distinguished road
Send a message via AIM to Mathiau Send a message via MSN to Mathiau Send a message via Yahoo to Mathiau
Default AD Security groups not being used for policies / webfiltering??

So this is a mix between Directory Connector, Policy Manager and webfilter, i think..

i have Policy manager set up by department, each department has their own rack and webfilter configuration with the parent rack, Default rack, being used for everything else, firewall, spyware et cetera.

Now in my Active directory i have same set up, Ogranizational Units for each department, and then with in those the Users and also Security Groups

So for example i have
MyDomain / Workstations OU /
Customer Service OU
- CS (Security Group)
- Joe blow
- Mary Jane
- Elvis
- Tu Pac

Now, all of the users are in the CS security group, i use this to make life easier when adding GPO's to our domain and use the Security groups to add instead of having to add 20+ individual users to things for access.

In policy manager i am doing the option for

Users
the users you would like to apply this policy too

Now we had a new employee join the company and so i created his account under the Customer Service OU and added him as a member to the CS security group.

I was reviewing the reports and he was having full access to all sites, which it shouldnt since the Customer Service Policy / Rack is set to fairly restrictive.

Checking Directory Connector, it seems like it either isnt updating and adding the Security groups i have made and it only is including users?

Attached is the select user section from policy manager

those groups, dont show in my Directory connector list when i query the users.
Attached Images
File Type: jpg Groups.JPG (54.5 KB, 12 views)
__________________
Def1:Started:UT 7.1 x64 -- Current :UT 9.1 x64| Gigabyte GM-G31 mATX | Intel Q8200 | 8G DDR2 800 | 80G WD | 4x Intel Pro 1000 GT NIC's | Corsair 550W PSU | Norco RPC-250 2U Case | 50mb/50mb | 10 users
Mathiau is offline  
Old 11-18-2011, 12:39 PM   #2 (permalink)
Untangle Ninja
 
Mathiau's Avatar
 
Join Date: Feb 2008
Location: Costa Frickn' Rica
Posts: 1,467
Mathiau is on a distinguished road
Send a message via AIM to Mathiau Send a message via MSN to Mathiau Send a message via Yahoo to Mathiau
Default

thoughts?
__________________
Def1:Started:UT 7.1 x64 -- Current :UT 9.1 x64| Gigabyte GM-G31 mATX | Intel Q8200 | 8G DDR2 800 | 80G WD | 4x Intel Pro 1000 GT NIC's | Corsair 550W PSU | Norco RPC-250 2U Case | 50mb/50mb | 10 users
Mathiau is offline  
Old 11-18-2011, 05:06 PM   #3 (permalink)
Untangle Ninja
 
hlarsen's Avatar
 
Join Date: Jul 2010
Location: sfba
URLs submitted: 1
Posts: 1,137
hlarsen is on a distinguished road
Default

do any security groups show up perhaps under other OUs?
__________________
Attention: Support on the Untangle Forums is provided by volunteers and community members.
If you need official Untangle support please call or email support@untangle.com.
hlarsen is offline  
Old 12-20-2011, 09:47 AM   #4 (permalink)
Untangle Ninja
 
Mathiau's Avatar
 
Join Date: Feb 2008
Location: Costa Frickn' Rica
Posts: 1,467
Mathiau is on a distinguished road
Send a message via AIM to Mathiau Send a message via MSN to Mathiau Send a message via Yahoo to Mathiau
Default

just an update, i updated to 9.1, i scrapped all of my racks and redid them, just put in my first rack and policy and added only the AD OU to the users list and it is picking people up now!
__________________
Def1:Started:UT 7.1 x64 -- Current :UT 9.1 x64| Gigabyte GM-G31 mATX | Intel Q8200 | 8G DDR2 800 | 80G WD | 4x Intel Pro 1000 GT NIC's | Corsair 550W PSU | Norco RPC-250 2U Case | 50mb/50mb | 10 users
Mathiau is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 05:02 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2