LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #4  
Old 06-Oct-2009, 01:11 PM
Senior Member
 
Join Date: Aug 2008
Posts: 1,634
phxazcraig 0 reputation points
Default Re: proxy authentication

In article <4ACAF8B8.CE15.0032.0@N0_$pam.vrapc.com>, Chris wrote:
> Would this allow rule be set as rule 1, or at least above
> all rules using user/group/containers ??
>

Think of two passes:

1. Look for allow rules, calling out source=IP address or Any. Skip
other rules. (Therefore the position of these rules compared to
nds-source rule doesn't matter).
2. Second pass, look for nds source rules.

You get into trouble when you have something like a SurfControl deny
rule followed by an Allow Any URL. With selective authentication,
everyone ends up going to the Allow Any URL, even if you had a
deny-this-group rule above it.

Craig Johnson
Novell Support Connection SysOp
*** For a current patch list, tips, handy files and books on
BorderManager, go to http://www.craigjconsulting.com ***


Reply With Quote
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -6. The time now is 06:56 PM.


© 2007 Novell, Inc. All Rights Reserved.

Search Engine Friendly URLs by vBSEO 3.3.0 RC2