Do you recognize a good idea when you see one? We want to hear from you!
Header Image

I suggest you ...

Authentication: Dedicated AD / LDAP Server Agent

We would like a program(s) that could install directly on our Active Directory or LDAP server that would update the appliance on what user currently has what IP(s). This way their user objects could be automatically kept current without the need of the Client-Agent you offer, and give me super precise control by User.

1 vote
Vote
Sign in
Check!
(thinking…)
Reset
or sign in with
  • facebook
  • google
    Password icon
    I agree to the terms of service
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    Angelo ComazzettoAdminAngelo Comazzetto (Product Ninja, Sophos Features & Ideas Laboratory) shared this idea  ·   ·  Flag idea as inappropriate…  ·  Admin →
    Peter MlekusPeter Mlekus shared a merged idea: LDAP with packet filter rule  ·   · 

    3 comments

    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      Submitting...
      • Angelo ComazzettoAdminAngelo Comazzetto (Product Ninja, Sophos Features & Ideas Laboratory) commented  ·   ·  Flag as inappropriate

        Hi Peter, you can accomplish this by installing the Astaro Authentication Agent (Sophos Authentication Agent in UTM9) which will report/update a user object with their current IP after being installed on a workstation. We are working on various improvements to this agent.

        Further, we will look at a dedicated server agent for the future as well, which I'll merge this one into.

      • Peter MlekusPeter Mlekus commented  ·   ·  Flag as inappropriate

        Hi,
        i now that i can do this with the user ho ar in the astaro but can i do this to a AD user ho gets authorized over ldap. I use http proxy and i have groups for the AD. Can i make packet filter rules for this users or groups or not, i can make the packet filer rule but will it work ???

      • Bob AlfsonBob Alfson commented  ·   ·  Flag as inappropriate

        Peter, if I understand your issue correctly, I think you can do it now. For each user, the Astaro creates a network definition. My username is "balfson" and the Astaro has a definition "balfson (User Network)" that can be used in packet filter rules

      Feedback and Knowledge Base