Project

General

Profile

Actions

Feature #13786

open

ldap intergration for firewall rules

Added by Mike Moore over 1 year ago. Updated 11 months ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Rules / NAT
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Release Notes:
Default

Description

Seeing as there are LDAP connectors in the software already for authentication, would it be possible to leverage that for firewall rules?
Creating a permit/deny rule based on source 'LDAP\User1". This feature alone would be "nextgen" for pf.

On other vendors, this does require an agent being installed on an AD server to get that updated directory list to map IP addr to username. But i think that would only be helpful for reporting/analytics. If we need to just validate the username and thats it, then i think this is possible. Other packages such as Squid can be leveraged if reporting is needed to see what sites were visited and when.

Actions

Also available in: Atom PDF