Good evening,
This email is in regards to the domain controller portion of E-smith and the proxy-auth module that requires user authentication.
If I'm understanding some of the postings correctly in this board, the proxy-auth will use the login information from a Windows 9x/ME machine if the user logs into the machine locally. The message didn't elaborate on whether it could be done if they logged into a domain other than the e-smith box.
I'm basically looking for a way to control access to the Internet and have come to the conclusion that I'll spend the $30 for the dungog.net module for DansGuardian and the bandwidth limiter.
With this in mind, here are some basic questions:
1. If I currently have a W2k domain, can the E-smith box join that domain so that it will use the userlist of the W2k domain rather than it's own?
2. If the E-smith box can join the domain, were the messages correct in stating that E-smith will use the login information from a Win 9x/ME box?
3. Can E-smith be a domain controller along with other W2k controllers? If not, can it be a domain controller of its own domain and have a trust relationship with the W2k domain?
4. If a trust relationship is there, can the proxy-auth module read the login information from the Win9x/ME machines through the trust relationship without having to setup users on the E-smith box?
5. Does the bandwidth limiter in dungog.net's module also limit the downloads, according to type, with files downloaded through kazaa and other like minded file-sharing programs?
6. I installed the ACID/Snort module and was looking for a way to automatically have the logs emailed to me and then clear them from the system on a scheduled basis.
7. Also, is there a way to have the same thing done with SARG? For example, have it email the monthly log and clear out the other two types of logs as well as the monthly one?
8. I also noticed on some of the postings that someone was working on finding a solution to the problem of users not being able to see the SARG reports even though they had installed the user panel module and gave the appropriate access. Any ideas on this issue?
9. I looked at IPCOP and liked one of the add-ons that emailed the traffic stats to the admin of the system, is there anything like that for E-smith?
10. I haven't seen anything about this on dungog.net's site concerning a DansGuardian log analyzer like SARG. If I install the proxy-auth module along with the dungog.net Dansguardian module and SARG, will the SARG reports give me any information? Also, will the SARG reports include the username as well as the rest of the information that SARG already gives?
11. I noticed that the Snort/ACID module had the option of Guardian being installed. From what I understood about the Guardian module was that it would disable access based upon security violations. I wasn't clear if this was for the whole network or just the internet. I have a friend that manages a vo-tech school's network and he has installed SmoothWall. He uses static IP addresses and he liked the ability of the DansGuardian module for SmoothWall that would disable internet access if they violated the content filter so many times. Anything like that in the DansGuardian/dungog.net modules?
Well, I guess that's enough for now.
I appreciate all your advice.
Wally