Old 10-28-2008, 07:25 AM   #1 (permalink)
Newbie
 
Join Date: Sep 2008
Location: Marlboro, MA
Posts: 2
unklebk is on a distinguished road
Default Logging in Locally and not on a AD Domain

We have a customer that has a question regarding the AD connector. They have the AD connector working fine that this location when the users login to the windows domain. The question is if the user does not login to the domain, but instead uses the local account on the workstation and does not run the AD login script, what if any filtering stop gaps are now in affect ? The Users ID will not be present to identify any filtering, and they use DHCP not static IP's for the workstations. Can the user bypass running the login script and filters to get out to the internet when they were previously locked down.

Thanks for any input on this !!!
unklebk is offline  
Old 10-28-2008, 09:38 AM   #2 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

Welcome,

That would only happen if you configured a policy to specifically redirect a user name into a custom rack. More than likely you just configured the default rack, which all users are subject to.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 10-29-2008, 08:04 AM   #3 (permalink)
Newbie
 
Join Date: Sep 2008
Location: Marlboro, MA
Posts: 2
unklebk is on a distinguished road
Default Thanks

Ok I see. So even if the user is a local user on that machine, I should be able to script the user in to the restricted rack that is setup now if I read you correctly.
unklebk is offline  
Old 10-29-2008, 09:37 AM   #4 (permalink)
Newbie
 
Join Date: Mar 2008
Location: The other Washington
Posts: 12
kirkalmquist is on a distinguished road
Default

Without knowing all the details as to why they would even be allowed to log onto the local machine when running in a Windows AD enviroment, my suggestion would be to talk the customer into removing all local accounts...

Just my 2 cents worth as a network admin
kirkalmquist is offline  
Old 10-29-2008, 09:41 AM   #5 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

Quote:
Originally Posted by unklebk View Post
Ok I see. So even if the user is a local user on that machine, I should be able to script the user in to the restricted rack that is setup now if I read you correctly.
No actually I was pointing out the exact opposite.

Untangle only has the ability to use Active Directory accounts to redirect traffic. Technically speaking from what I have seen of the Active Directory script it may be possible to have it pick up a local account and pass that information to Untangle... but you're moving in a custom (unsupported) direction.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 05:12 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2