Results 1 to 10 of 10
  1. #1
    Untanglit
    Join Date
    Jan 2009
    Posts
    25

    Default Ok, I'm missing something....

    Ok, I don't get it. I've got a tiny domain at home (win2k3 AD). For the family. Kids are getting older and wanting time on the computers, but I want to block them from the nasty stuff.

    Searching around for a good firewall/web filter that will work with AD and so I end up here.

    Untangle looks awesome and simple and free/cheap. So I install it. It IS awesome and simple and free/cheap!

    So what I want to do is create rules based on Groups. I can't do that. Fine, because I can create separate racks with filters that will allow me to group users and give different accounts different access.

    Like I said this is for my home network so it's not a huge problem to manage the racks this way. I want an "adults" rack and a "kids" rack. So I create them. in the Policy Manager I set a rule that should say if the AD user is "Kid1" or "kid2" then use the "NoPorn" Rack. In the No Porn Rack i have web filter set up to block bad stuff.

    It doesn't work. I assume because I ONLY set AD user names as the criteria. From everything I've read - you HAVE to put in an IP. Well...what if I want to go to the kids room to fix something and need access to stuff I'm not giving them? or what if the kids go on the main PC and want to log on and do stuff? it seems to ONLY be filtering by IP...so my question is...

    if it has to be done by IP, what's the point of having (and eventually paying for) the AD Connector and Policy Manager? as far as I can tell the AD connector doesn't really do anything except let you pull names...but not actually do anything with them.

    what is it that I'm missing here?

    Thanks!

  2. #2
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,912

    Default

    Your AD connector is misconfigured or something is wrong. I use AD user names to route to racks all the time. That is the point of the AD Connector as it integrates with the policy manager.

    Now, in my case the AD's I use this on are all 2k3 like yours. I can tell you that the configuration of the AD connector is a bit more annoying than it should be.

    Can your AD connector actually see a list of users? If that screen isn't pulling the user list your AD connector needs help.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    rob@intouchtechllc.com

    UntangleAppliances.com
    Phone: 866-794-8879

  3. #3
    Untanglit
    Join Date
    Jan 2009
    Posts
    25

    Default

    Yes, it pulls the list of users, I put check boxes next to them.

    I know the rule is set right because if I put my IP it works, it just doesn't seem to work by user name.

  4. #4
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,912

    Default

    Do you have the login script running on the client? Without it Untangle has no way to match the user to the IP they are using.

    https://untangleip/adpb/debug

    Use the above URL and it will show you the current map of users to IP address. If that map isn't populating, your policies have nothing to go on.
    Last edited by sky-knight; 01-29-2009 at 12:07 PM.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    rob@intouchtechllc.com

    UntangleAppliances.com
    Phone: 866-794-8879

  5. #5
    mdh
    mdh is offline
    Untangle Ninja mdh's Avatar
    Join Date
    Aug 2007
    Posts
    4,802

    Default

    That script is essential for it to work. I also read carefully, and while I read that you have a domain, I did not read that people actually have to login TO the domain. No domain login -> no group policy -> no script
    This space reserved for profound thought.....which does happen on occasion."

  6. #6
    Untanglit
    Join Date
    Jan 2009
    Posts
    25

    Default

    Quote Originally Posted by sky-knight View Post
    Do you have the login script running on the client? Without it Untangle has no way to match the user to the IP they are using.



    Use the above URL and it will show you the current map of users to IP address. If that map isn't populating, your policies have nothing to go on.
    Current user table:

    BLANK!

    I think you're on to something here. I read a bunch of stuff but didn't see anything specific about scritps. I have NO problem doing this...just....what am I supposed to do? I assume this is something I'll have to call from the AD login script?

    Its not fixed yet, but you've at least let me know what I'm probably doing wrong so far.

    Thanks!!!

  7. #7
    Untanglit
    Join Date
    Jan 2009
    Posts
    25

    Default

    Quote Originally Posted by mdh View Post
    That script is essential for it to work. I also read carefully, and while I read that you have a domain, I did not read that people actually have to login TO the domain. No domain login -> no group policy -> no script
    yeah, sorry. you're good. Yes, all the PCs are members of the domain and the plan is to make everyone log into it.

  8. #8
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,912

    Default

    Look in the AD Connector rack module, just below the AD Test button, there is a button to download the AD Script.

    That Script has to be installed in your DC's login script area in Sysvol

    The easy way to see it is to look at your server's NETLOGON share.

    \\server\NETLOGON

    Put the VBS file in there, and get into group policy and assign it as a login script for the everyone group. Then relogin with a domain account and you should see wscript.exe running in task manager, and use the above debug to see your current user name and IP listed.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    rob@intouchtechllc.com

    UntangleAppliances.com
    Phone: 866-794-8879

  9. #9
    Untanglit
    Join Date
    Jan 2009
    Posts
    25

    Default

    Thanks a lot. I feel like a total tool for missing that in the documentation. Through the AD setup, I just breezed through. Thought....cool, it's working when it pulled back the list of names. FAIL!

    thanks a ton sky-knight and mdh!

  10. #10
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,912

    Default

    Well hey you get props for coming here looking for one of the rarest features in the security market. Granted, it isn't perfect, and if you read that script you will see why. But it does rather nicely allow you to control user access on a human level. It's always nice to get a way to attach process logic to the people that we want to protect, instead of the machines they are using.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    rob@intouchtechllc.com

    UntangleAppliances.com
    Phone: 866-794-8879

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2