D-Link DFL-1000 [59/168] Requiring authentication to connect to the internet

D-Link DFL-1000 [59/168] Requiring authentication to connect to the internet
DFL-1000 User Manual
5
9
If you are using accept policies to restrict access, you must remove all general access policies, such as
the default policy, that could be matched by a connection that you do not want. For more information, see
Policy matching in detail
and Configuring policy lists.
Requiring authentication to connect to the Internet
To require authentication, you must add users and user groups to the firewall configuration (see Users
and authentication). You can then add policies to require users to enter a user name and password to
access services through the firewall.
You can require authentication:
for policies between any two interfaces,
to connect to selected addresses,
according to a schedule.
You can select authentication for any service. Users can authenticate with the firewall using HTTP, Telnet,
or FTP. For users to be able to authenticate, you must add an HTTP, Telnet, or FTP policy that is
configured for authentication. When users attempt to connect through the firewall using this policy, they
are prompted to enter a firewall user name and password.
If you want users to authenticate to use other services (for example, POP3 or IMAP), you can create a
service group that includes the services for which you want to require authentication as well as HTTP,
Telnet, and FTP. Users can then authenticate with the policy using HTTP, Telnet, or FTP before using the
other service.
In most cases, you should make sure that users can use DNS through the firewall without authentication.
If DNS is not available, users cannot connect to a web, FTP, or Telnet server using a domain name.
The following example procedure describes how to configure the firewall to require users on the internal
network to authenticate to access POP3 servers on the Internet. In this example, the DFL-1000 NPG is
running in NAT/Route mode, but the configuration would be the same for a DFL-1000 NPG running in
Transparent mode.
To require authentication:
Add at least one user group to the firewall.
See Users and authentication
.
Go to Firewall > Service > Group .
Select New to add a Service Group.
Enter a Group Name for the New Service Group and add the POP3, HTTP, FTP, and Telnet services
to the service group Members list.
Go to Firewall > Policy > Int->Ext .
Select New to add a new policy.
You can also select Insert Policy before
on a policy in the list to add the new policy above a
specific policy.
Configure the policy to match the type of connection for which to require authentication:
Set Service to the service group that you added in step Enter a Group Name for the New Service
Group and add the POP3, HTTP, FTP, and Telnet services to the service group Members list..
Set Action to ACCEPT.
Select Authentication and select the user group that you added in step Add at least one user group to
the firewall..
Select OK to save the policy.
You must add the policy requiring authentication above the default policy and above any matching accept
policies in the policy list. For more information, see Policy matching in detail
and Configuring policy lists.

Содержание

Скачать