by ChrisH » Dec 09 03 4:00 am
Hi Adrien,
Thanks for reply. I understand about per service policies as you indicate but I was assuming that policies for each individual service were seperate. So, I gather from what you are saying is that policy in WWW proxy is kind of .OR.'ed with ENS or WRS policy IF TR is enabled. If policy in WWW proxy allows it but policy in WRS doesn't, the right is granted, - seems to be the case. But it doesn't work the other way. If policy in ENS allows it and WWW proxy doesn't, then right isn't granted. The only policy that seems to be different is authentication. If WRS wants authentication and WWW proxy doesn't (or vice versa), user must authenticate.
My scenario is that I want to restrict one user from using NAT for anything after a certain time, but if WWW proxy allows it, the user can browse, so I have to have a duplicate time policy for that user created in WWW proxy. OK, so I might be lazy and only want to do things once, but I was hoping I could get away with it. Is it supposed to be this way? If it is, is it possible to add a feature request so that one doesn't have to do things twice? Using 5.2. TIA
Chris H.