News: This forum is now permanently frozen.
Pages: [1]
Topic: CaptivePortal Network/IP addresses Allowed  (Read 1887 times)
« on: March 23, 2010, 11:50:16 »
thorus *
Posts: 1

Hi all,
I'm using Monowall since a while now and i'd like to know if there is a "good" "elegant" solution to my issue :

Short Version :
Is there any way to add "Allowed Networks" to the captive portal ?
For a /24 network for example, i *really* ;) dont want to add all 254 machines IP by IP to allowed IPs, but directly add them all as an Allowed Network, to pass the captive portal without being taken...For example, add all the DMZ network to be abble to pass the CaptivePortal to access to all of my servers on a dedicated separate network.

Long Version :

I have Captive Portal activated on lan interface with a classic user-managment.
On the other hand, i have a ipsec gateway (the IPSec gateway is *not* the monowall firewall but an OpenBSD server on a dedicated network running isakmpd as IKE daemon), and i added static routes on Monowall to be abble to access to my ipsec tunnels from the lan (which is a basic IPSec configuration) : everything just work fine :)

Now, the thing is that if I enable the Captive Portal, i'm not abble to access to my ipsec tunnels unless I log into the captive portal. So, I added some IPs as allowedIPs to pass the captive portal without being taken. It works fine too :)
The probleme is that i'm going to have some additionnals networks as IPSec traffic endpoints and i *really* dont want to add allowed IPs IP by IP...

So I'd like to know if there's a way to add "Allowed Network" and not just "Allowed IPs"  to the captive Portal.
The official documentation about Allowed IPs (http://doc.m0n0.ch/handbook/captiveportal.html#id11640244), for example, says that if we have servers listening on a separate network, we shoud add their IPs in the Captive Portal to allow users to access then without being taken... I'd say what if those servers are on a DMZ and you'd like to add *all* the DMZ (as a whole network and not only IP by IP)  to the captive portal ? Is that possible ? Or in the pipe (maybe a feature request ;-) )

Thank you all.

 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines