Hi,
I am a long time BorderManager user considering moving on to new and not secret till the last minute and already EOL things. BorderManager has been very very good to me except the 3.8 BS VPN that never really worked the way that it should have. It has very powerfull filtering possibilities and I need them in the future. Can anyone tell me if the example below is possible and give basic examples how it would be configured so that dumb ol me can test it?
Basics:
-nobody can surf if they are not in the www_users group.
-nobody can use https except certain general exceptions.
-no ebay, webmailers und co.
-.exe, .com, .pif, mp3 .. are no-nos
ACLs configured in BM:
1. Deny
- *.exe
- *.com
- *.... several others
for all
2. Allow:
- https://*.lufthansa.com
- https://*.ba.com
- https:// ... several others
for group www_https
3. Allow:
- ftp://*.novell.com
- ftp://*.mcafee.com
- ftp://*.... several others
for group ftp_users
......
8. Allow http thru proxy ( port 80 ) for www_Users
9. Deny rest.
Generally, all www_users can surf normal, non-webmail / ebay and Co. sites. No FTP, https or executable downloads. I must be able to control the access on a group basis ( just toooooo many users ) and many users belong to more than one group. This means that a multiple profile/acl configurations and checks for one group must be possible.
Can Astaro support something like this? I found something in the manual ( yea, I RTFM but it isn't quite enough ) that stated that multiple profile assignment checks per "local user" were not possible but it did not state if that goes for groups also.
Can anyone provide some infos on this. I really like what I've seen of the ASG but am not quite sure if it can do what I need it to.
Thanks,
Daryn
This thread was automatically locked due to age.