• February 24, 2025, 08:21:58 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: Is it possible to restrict access to the WWW on a per user basis  (Read 4904 times)

djm

  • Level 1 Member
  • *
  • Posts: 21
Is it possible to restrict access to the WWW on a per user basis
« on: November 16, 2009, 03:45:29 PM »

Hi,

I have set up 2 IP rules - one allow for a specific range of LAN addresses on HTTP-outbound and one deny on all LAN addresses on HTTP-outbound.

This effectively only allows certain computers to be able to browse the web.

Is it possible - probably using User Authentication - to set it up so that when anybody on any of the LAN's computers attempts to browse the web they get asked for user/password to authenticate and only if successful do they get on the Web?

Thanks,

David.
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: Is it possible to restrict access to the WWW on a per user basis
« Reply #1 on: November 17, 2009, 08:30:12 AM »

Sure, the below FAQ should be a start for you, be very careful about mimicking it perfectly and it will work.

This is a very easy one to get one step wrong on and end up with a 90% correct config and 20% of the functionality you had before you started.

For that reason I would add the IP Rules you are going to create to a folder below your original outbound rules, and then disable your original outbound rules while testing.  Then you have the ability to reverse most of your changes with a couple clicks.

http://www.dlink.com/support/faq/?prod_id=2395
Logged
non progredi est regredi

djm

  • Level 1 Member
  • *
  • Posts: 21
Re: Is it possible to restrict access to the WWW on a per user basis
« Reply #2 on: November 25, 2009, 04:05:09 AM »

Hi Fatman, thanks for offering some help.

I implemented the link that you gave.  On one of the computers on the LAN, if I then attempt to use a browser to visit say www.google.com I get access to the site without being asked for a username etc.  If I enter the LAN IP of the DLink I then get asked for a login.  But what point is that login.  It neither gives nor denies access to the general Internet which is what I was hoping to do.

Any other ideas?

Thanks,

David.
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: Is it possible to restrict access to the WWW on a per user basis
« Reply #3 on: November 25, 2009, 09:20:26 AM »

Then you either did not set up the port forward section of the FAQ correctly, or you failed to make the authenticated IP group correctly, or you didn't put the rules in the right order.
Logged
non progredi est regredi