Re: PF and AD

2007-05-05 Thread Peter N. M. Hansteen
"Ricardo Benq" <[EMAIL PROTECTED]> writes: > Is it possible to make filter rules that are based on Microsoft Active > Directory users? If you can have the sshd on your pf equipped gateway use authentication data from your Microsoft system (which is sort of LDAPish), the next (and possibly smaller

Re: PF and AD

2007-05-04 Thread Max Laier
[ Please don't top post - it reverses the communication flow ] On Friday 04 May 2007, Ricardo Benq wrote: > > Ricardo Benq wrote: > > >Hello. > > >Is it possible to make filter rules that are based on Microsoft > > > Active Directory users? > > >Do I have to install samba/winbind? Are there tutori

Re: PF and AD

2007-05-04 Thread Ricardo Benq
Ok, Gregory, here it goes: In our network, all users are AD domain users that have access to services/networks restricted by AD groups. We already have a SQUID/Dansguardian that filter internet access for AD user/groups via ACLs for radio, video, messenger, etc. All Active Diretory users are au

RE: PF and AD

2007-05-04 Thread Kevin K.
The only thing I can think of is if maybe the firewall uses the Microsoft server as DNS, and you should be able to resolve computer names and write rules in PF accordingly. I am planning on implementing a couple FBSD PF boxes in front of some Windows servers, so it would be interesting if anyone e