Switch to full style
Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems
Post a reply

Computer restriction with NAT

Oct 07 05 6:22 am

Hi.

We have a 6 user licenseand the newest version of wingate installed.
I'm using NAT and want a completely transparent sollution without having to comfigure proxy on the clients.

Right now, every computer on the network can acess internet, but is there some way to restrict the "guest" account to only acess f-secure and windows update for instance?

Then using "assumed users" I guess I can give computers on the network full acess to the internet.

How do I set this up?

Oct 07 05 4:17 pm

To do this, you would.

1. create user accounts in WinGate for each user you want to be able to track.
2. Create a group, call it maybe "allowed access", add all the users to this group, except the Guest user.
3. For each user, create an "Assumed user" entry, which links their IP to their username.

Now, when your users connect, they will show up with their assumed username in GateKeeper.

Then, go into the WWW proxy, and select the Policies tab.

1. at the bottom, select "are ignored" for default policies
2. Add a policy, under who is allowed, select the group "allowed access", or whatever you called it before and "user may be assumed".
3. Click OK.

Now your users have access to anywhere, except Guest has no access to anything. To fix this, add another policy in the WWW Proxy.

In this case, choose "anyone", but allow unknown. Then you go to the advanced tab and add a filter for each site you want Guest to be able to access.

That will grant Guest access to the sites you enter.

Adrien
Post a reply