Operating System - HP-UX
1753821 Members
8728 Online
108805 Solutions
New Discussion юеВ

access control list (grand access to users by throug ip(subnet))

 
siva baskaran
Regular Advisor

access control list (grand access to users by throug ip(subnet))

Hi,

i have created(restricted) couble of user id and subnet (10.10.x.x), so here i have two scanrio one user id another is subnet,
now I want to allow users from particular ip address only (like 10.10.X.X) only, they should use particular user id which i have created and given information to them.

and like whoever login through other subnet system should denied,

in this case some users has two id, one is normal id another is which i have created(restrcited.

think simply to say is access control list by Ip wise

so can anybody have any idea,steps or any script to filter on this query please share with would most helpfull

Thanks & Regards
Siva
3 REPLIES 3
Jeeshan
Honored Contributor

Re: access control list (grand access to users by throug ip(subnet))

you can set the rule in /var/adm/inetd.sec file and restart the inetd daemon.
a warrior never quits
siva baskaran
Regular Advisor

Re: access control list (grand access to users by throug ip(subnet))

Thank you ahsan,

but as per your recommandation, what ever ip address/ subnet/hostname I puting entry in /var/adm/inetd.sec file only be able to login correct ?

i am giving one scanrio :

one user has two id, one id has admin rights another not, here whenever he logins from intranet system should allow him by admin Id,

and whenever he logins from internet (like through VPN) system should allow him by non-admin user ID (restricted Id)at any cost he shouldn't use admin user id from internet or system shouldn't allow him login as admin through internet(VPN).

this is nothing but different subnets, and just like mapping sunbnet with user id.

now how can I ?

Ivan Krastev
Honored Contributor

Re: access control list (grand access to users by throug ip(subnet))

Hello Siva,

How your users connect to the server - ssh, telnet?

You can use also tcpwrappers, script in /etc/profile to restrict access.

regards,
ivan