Re: Iinternet access control..
- From: "Geir Holmavatn" <geir2@xxxxxxxxxxx>
- Date: Tue, 21 Feb 2006 18:14:22 +0100
"Jan Sevelsted" <NOsevelstedSPAM@xxxxxxxxxxxxxxxxxxxxxxxx> wrote in
news:pan.2006.02.15.22.15.46.3004@xxxxxxxxxxxxxxxxxxxxxxxxxxx
I'm having a similar task here. Provide a bunch of young people with
Internet access in a way so that if they clash with the rules, they can be
'relieved' of the possibilities of the big web.
This I intend to accomplish by using freesco v 0.34. It has some abilities
that enables me to do it easily.
Plan A:
1) Set up forwarding so that no-one in the subnet is allowed to go out.
2) Set up restrictions to allow specific NIC's (MAC/IP combinations) to go
out. This calls for contacting the SysAdmin in order to get a working
connection.
3) Set up DHCP-service to provide static leases to each known
NIC.
4) In combination 2 and 3 ought to cut out the industrious ones
bringing in another PC to circumvent restrictions - an unknown NIC does
get a DHCP-lease and can participate in game-parties etc. but is not
allowed to access the web.
5) Logging of DNS-lookups etc in order to catch the ones that just had to
try the forbidden fruit anyway. Result: Quarantined for one month (or what
the going rate will be).
Very interesting,
Would it be a problem if the MAC > IP lookup list grew to 300+ entries?
We have an Ubuntu box just acting as a firewall for this network now. Would
it be possible to implement something like the scenario above under Ubuntu
too? Which software would I then need?
Thanks again for opinions on these details
Geir
.
- Follow-Ups:
- Re: Iinternet access control..
- From: Jan Sevelsted
- Re: Iinternet access control..
- References:
- Iinternet access control..
- From: Geir Holmavatn
- Re: Iinternet access control..
- From: prg
- Re: Iinternet access control..
- From: Geir Holmavatn
- Re: Iinternet access control..
- From: prg
- Re: Iinternet access control..
- From: Geir Holmavatn
- Re: Iinternet access control..
- From: prg
- Re: Iinternet access control..
- From: Jan Sevelsted
- Iinternet access control..
- Prev by Date: Re: ADSL USB Modem
- Next by Date: Re: Does "virtual hosting" for SSH with netfilter exist ?
- Previous by thread: Re: Iinternet access control..
- Next by thread: Re: Iinternet access control..
- Index(es):
Relevant Pages
|