Re: PF and LDAP

2009-07-31 Thread Stuart Henderson
On 2009-07-31, Marcello Cruz wrote: > Thanks Chris! Thanks everybody! I was not clear, my mistake. I'm sorry. > > The idea is to allow traffic from a computer on the inside network to pass > the traffic to the outside network (Internet) using some directory service > based on LDAP (Active Direct

Re: PF and LDAP

2009-07-31 Thread Chris Dukes
On Fri, Jul 31, 2009 at 08:58:26AM -0300, Marcello Cruz wrote: > Thanks Chris! Thanks everybody! I was not clear, my mistake. I'm sorry. Please do not top post and if you are not going to respond to specific bits of quoted text, delete the quoted bits of text. Thanks. > > The idea is to allow tr

Re: PF and LDAP

2009-07-31 Thread Marcello Cruz
trying to avoid future problems regarding security. Rgds, Marcello - Original Message - From: "Chris Dukes" To: "Marcello Cruz" Cc: Sent: Thursday, July 30, 2009 11:47 PM Subject: Re: PF and LDAP On Wed, Jul 29, 2009 at 01:42:44PM -0300, Marcello Cruz wrote:

Re: PF and LDAP

2009-07-30 Thread Chris Dukes
On Wed, Jul 29, 2009 at 01:42:44PM -0300, Marcello Cruz wrote: > Dear all, > > Is there a way to use LDAP in a rule to allow or deny based on the user > instead of the IP Address? Okay, I'm going to be literal here... ypldap to map LDAP to NIS. Configure the box to allow users to be resolved by

Re: PF and LDAP

2009-07-30 Thread Фролов Константин
30.07.09, 13:55, "Marcello Cruz" : > Dear all, > Is there a way to use LDAP in a rule to allow or deny based on the user > instead of the IP Address? > The idea is to permit the traffic from an inside user to access, for example, > a VoIP resource on the Internet. Based on user... I use for this

Re: PF and LDAP

2009-07-29 Thread Bob Beck
* Marcello Cruz [2009-07-29 10:51]: > Dear all, > > Is there a way to use LDAP in a rule to allow or deny based on the user > instead of the IP Address? Define "user" - in the context of IP. last time I looked no such thing was in there. authpf comes close, but remember, traffi