Re: Only allow authenticated domain users Internet access?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Herb Martin (news_at_LearnQuick.com)
Date: 02/10/05


Date: Wed, 9 Feb 2005 21:05:45 -0600


"Björn" <Bjrn@discussions.microsoft.com> wrote in message
news:DDE2E3A0-D4EA-4089-B00F-2F6CBDEF9999@microsoft.com...
> I work at a small high school (about 400 students). Our students connects
to
> use portable computers with both Windows XP and Mac OS X. They connect to
our
> LAN via a wireless connection with a MAC-address validation process. All
> students have an account on our domain controller (Windows2003). But many
> students choose not to log on to the domain, hence not getting essential
> network shares and global policies. I would like to stop these users from
> getting Internet access.
>
> This is how I would like it to work:
> Only users who are logged in to the domain should be allowed Internet
> access. All other users should only have access to the LAN or even better
> only to the DC.
> Is this possible to do? What kind of hardware/software do I need?

> We have looked at the ISA-server. But the firewall client needed for user
> lever authentication is only available for windows clients. This would
lock
> out our Mac users, hence not an option.

You can run (what used to be called the) Web Proxy which requires
no ACTUAL new software. It will allows any Browser which can
support the client to authenticate the same as when they reach any
web site.

The open standard SOCKS proxy authentication method should
also work if the clients support it.

There is also support for
If you use the actual (add-on) client software then ...
How else would you authenticate a Domain User if the machines
are not "Domain Clients".

The limitation is not really an ISA one, but the authentication methods
and it supports at least three.

You might try the question on the ISA for specifics.

-- 
Herb Martin
> -- 
> Björn Blissing
> MSc Media Technology
> Norrköping, Sweden


Relevant Pages

  • Re: help on masquerading
    ... > your LAN and whenever anyone changes IP. ... Their purpose is to provide public Internet access and ... > people can decline authentication and be authenticated as anonymous, ... Restricting my customers with MAC address. ...
    (Debian-User)
  • Re: security of IP address
    ... >> MAC is really all you have to work with initially. ... be concerned with "continuous" dhcp message authentication. ... Bootup-logon authentication via ldap is used. ... clients and dhcp gateways. ...
    (comp.os.linux.networking)
  • Re: Give access based on location
    ... So regardless of where the user logs on from if he uses the same logon ... >> The next question would be how to do authentication from a MAC address? ... >>> You can restrict to certain network segments by using ACLs on the LAN ...
    (microsoft.public.windows.server.networking)
  • Whats gonna happen if two clients in the same LAN have the same MAC address?
    ... What's gonna happen if two clients in the same LAN have the same MAC ... server. ...
    (microsoft.public.windows.server.security)
  • Re: pine program and mail services with FC6 System
    ... protocols = imap imaps pop3 pop3s ... # Directory where authentication process places authentication UNIX sockets ... # chroot login process to the login_dir. ... # what most of your IMAP clients are. ...
    (Fedora)