Login restrictions

From: Nick Kraal (nick_at_arc.net.my)
Date: 11/17/03

  • Next message: Simon Gray: "Re: About DNS (BIND) with Database"
    Date: Mon, 17 Nov 2003 11:09:48 +0800
    To: freebsd-isp@freebsd.org
    
    

    I am trying to create shell accounts on a FreeBSD box for guests to access
    our network as an entry point. I need to restrict these guest so they do not
    roam freely, get too itchy and install stuff and play around. All they need
    to do is to ssh to the box to then telnet into our corporate network, that
    is all. ACLs on the corporate router permit access only from this box.

    So how do we do this:
    1. Jail- how-to's on this are not that clear and seem to be centric around
    BIND installations.
    2. chroot- again how-to's for this are poor and recommend jail instead -go
    to point #1.
    3. restricted shell- still finding this, somewhat like the nologin/noshell
    shell.

    Much appreciated if there are some pointers to good how-to's. I am more
    partial to a chroot environment being slightly more simpler to implement.

    Thanks in advance.

    -nick/

    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"


  • Next message: Simon Gray: "Re: About DNS (BIND) with Database"

    Relevant Pages

    • Re: Time server...how to set it up on FC1?
      ... Network Time Protocol is different from the "time" ... I suggest that you set up ntpd on your server. ... would set this to "restrict default ignore" and then allow access for your ... # Permit time synchronization with our time source, ...
      (Fedora)
    • Re: Restrict access to certain sites
      ... Establish what is accepted use of the Internet. ... network or anything being removed from the network, ... Monitor only - Track what's done. ... restrict their logon since they're using their own and will eliminate the ...
      (microsoft.public.win2000.dns)
    • RE: Create user that dont have access to domain
      ... If you are talking about PCs in public areas, ... listed below) and then restrict network object access using the GPO. ... Through a GPO or local policy? ...
      (microsoft.public.windows.server.active_directory)
    • Re: Deny access to copy files
      ... I can restrict SMTP and POP ports but when it comes to web based emails I am ... secure network that is fully encrypted. ... of removable media disabled in the BIOS. ... and keys must be stored separate from backups. ...
      (Security-Basics)
    • Re: Wireless security
      ... the MAC address of your computer to add to the router's 'Approved' list. ... The same password is used to give all computers (mine and guests) access ... to the wireless network. ...
      (uk.business.agriculture)

    Loading