{"id":31,"date":"2016-05-02T11:50:25","date_gmt":"2016-05-02T14:50:25","guid":{"rendered":"http:\/\/xaxowareti.com.br\/?p=31"},"modified":"2023-10-16T09:36:23","modified_gmt":"2023-10-16T12:36:23","slug":"pfsensesquidsquidguard-logando-no-active-directory","status":"publish","type":"post","link":"https:\/\/xaxowareti.com.br\/?p=31","title":{"rendered":"Pfsense+Squid+SquidGuard logando no Active Directory"},"content":{"rendered":"<h2 class=\"entry-title\"><a title=\"Permalink to Pfsense+Squid+SquidGuard logando no Active Directory\" href=\"http:\/\/www.pfsense-br.org\/blog\/2012\/01\/pfsensesquidsquidguard-logando-no-active-directory\/\" rel=\"bookmark\">Pfsense+Squid+SquidGuard logando no Active Directory<\/a><\/h2>\n<p>&nbsp;<\/p>\n<div class=\"entry-content\">\n<p>Na aba \u201cAvailable Packages\u201d procure por \u201csquid\u201d e mande instalar clicando no \u00edcone no canto direito<\/p>\n<p><a href=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/01.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-361\" src=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/01-300x152.png\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" srcset=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/01-300x152.png 300w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/01-1024x519.png 1024w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/01.png 1366w\" alt=\"\" width=\"300\" height=\"152\" \/><\/a><\/p>\n<p>Imediatamente voc\u00ea ser\u00e1 direcionado para a p\u00e1gina do Package Installer, nele veremos o progresso da instala\u00e7\u00e3o do pacote squid e suas depend\u00eancias:<\/p>\n<p><a href=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/02.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-362\" src=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/02-300x152.png\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" srcset=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/02-300x152.png 300w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/02-1024x520.png 1024w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/02.png 1366w\" alt=\"\" width=\"300\" height=\"152\" \/><\/a><\/p>\n<p>Vamos inserir as regras para a rede LAN:<\/p>\n<p><a href=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/04.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-367\" src=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/04-300x152.png\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" srcset=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/04-300x152.png 300w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/04-1024x519.png 1024w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/04.png 1366w\" alt=\"\" width=\"300\" height=\"152\" \/><\/a><\/p>\n<p>OBS.: LAN net = LAN subnet<\/p>\n<p>Agora vamos no menu Services &gt; Proxy Server:<\/p>\n<p>Na aba \u201cGeneral\u201d certifique que \u201cTransparent Proxy\u201d est\u00e1 desmarcada.<\/p>\n<p><strong>Considerando que seu servidor wk3 est\u00e1 com o IP: 192.168.1.12, a senha do usu\u00e1rio Administrador \u00e9 \u201cpwd1admin\u201d e seu dom\u00ednio \u00e9 prototipo<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>Na aba \u201cAuth Settings\u201d vamos adicionar os seguintes\u00a0par\u00e2metros:<\/p>\n<p>&nbsp;<\/p>\n<p>Authentication method: LDAP<\/p>\n<p>LDAP version: 3<\/p>\n<p>Authentication server: 192.168.1.12<\/p>\n<p>Authentication server port: 389<\/p>\n<p>LDAP server user\u00a0DN: cn=Administrador,cn=Users,dc=prototipo<\/p>\n<p>LDAP password: pwd1admin<\/p>\n<p>LDAP base domain:\u00a0dc=prototipo<\/p>\n<p>LDAP username DN attribute: uid<\/p>\n<p>LDAP search filter: sAMAccountName=%s<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-368\" src=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/05-300x175.jpg\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" srcset=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/05-300x175.jpg 300w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/05.jpg 1024w\" alt=\"\" width=\"300\" height=\"175\" \/><\/p>\n<p>OBS: Meu dom\u00ednio coloquei somente o nome prototipo, n\u00e3o coloquei nada como .com.br ou .com<\/p>\n<p>&nbsp;<\/p>\n<p>Ap\u00f3s este processo o squid estar\u00e1 buscando os usu\u00e1rios pelo Ad, agora precisamos instalar o SquidGuard para que ele possa controlar estes usu\u00e1rios na rede.<\/p>\n<p>V\u00e1 na aba Blacklist e baixe no site da shallalist os arquivos, ou cole na blacklist upload:<a href=\"http:\/\/www.shallalist.de\/Downloads\/shallalist.tar.gz\">http:\/\/www.shallalist.de\/Downloads\/shallalist.tar.gz<\/a><\/p>\n<p><a href=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/8.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-370\" src=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/8-300x175.png\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" srcset=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/8-300x175.png 300w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/8.png 1024w\" alt=\"\" width=\"300\" height=\"175\" \/><\/a><\/p>\n<p>V\u00e1 na aba Common ACL e acesse Target Rules List e de um Deny no Default access All<\/p>\n<p><a href=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/9.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-371\" src=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/9-300x175.jpg\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" srcset=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/9-300x175.jpg 300w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/9.jpg 1024w\" alt=\"\" width=\"300\" height=\"175\" \/><\/a><\/p>\n<p>Agora vamos adicionar em Group ACL os grupos que j\u00e1 temos cadastrados no Active directory.<\/p>\n<p>No meu exemplo tenho cadastrado somente dois, um deles \u00e9 \u201cInternet-TI\u201d \u201cInternet-Padrao\u201d, deixe-os\u00a0 com letras mai\u00fasculas ou min\u00fasculas do jeito que postou no Active Directory.<\/p>\n<p><a href=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/10.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-372\" src=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/10-300x175.png\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" srcset=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/10-300x175.png 300w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/10.png 1024w\" alt=\"\" width=\"300\" height=\"175\" \/><\/a><\/p>\n<p>Note que no campo cliente, possui alguns usu\u00e1rios, \u00e9 importante adiciona-los pois o SquidGuard vai bloquear de acordo com as especifica\u00e7\u00f5es que voc\u00ea adicionar\u00e1 logo em Target Rules list<\/p>\n<p>&nbsp;<\/p>\n<p>No meu exemplo, o Grupo Internet-TI ter\u00e1 bloqueado somente webmail.<\/p>\n<p><a href=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/11.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-373\" src=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/11-300x175.png\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" srcset=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/11-300x175.png 300w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/11.png 1024w\" alt=\"\" width=\"300\" height=\"175\" \/><\/a><\/p>\n<p>Para fazer o teste, clique em save e volte para a aba General Settings e deixe de acordo com a tela abaixo.<\/p>\n<p><a href=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/12.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-374\" src=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/12-300x175.png\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" srcset=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/12-300x175.png 300w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/12.png 1024w\" alt=\"\" width=\"300\" height=\"175\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Assim que o squidguard iniciar ficar\u00e1 com status start. A\u00ed \u00e9 s\u00f3 testar.<\/p>\n<p>Para fazer o teste fui no Internet Explorer e v\u00e1 em Ferramentas&gt;Op\u00e7\u00f5es da Internet&gt;Configura\u00e7\u00f5es da LAN<\/p>\n<p><a href=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/13.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-375\" src=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/13-300x260.png\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" srcset=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/13-300x260.png 300w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/13.png 614w\" alt=\"\" width=\"300\" height=\"260\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Configure de acordo com o Ip de seu PfSense.<\/p>\n<p><a href=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/14.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-376\" src=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/14-300x260.png\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" srcset=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/14-300x260.png 300w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/14.png 384w\" alt=\"\" width=\"300\" height=\"260\" \/><\/a><\/p>\n<p>Agora de um Ok e Ok<\/p>\n<p>Feche o navegador e abra-o novamente e agora coloque o login e senha do grupo que adicionou, no meu caso Internet-TI<\/p>\n<p>&nbsp;<\/p>\n<p>Agira vou acessar um site que contenha webmail. Ex: <a href=\"http:\/\/www.hotmail.com.br\/\">www.hotmail.com.br<\/a><\/p>\n<p><a href=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/111.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-377\" src=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/111-300x210.png\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" srcset=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/111-300x210.png 300w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/111.png 430w\" alt=\"\" width=\"300\" height=\"210\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Este \u00e9 o resultado.<\/p>\n<p><a href=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/222.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-378\" src=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/222-300x112.png\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" srcset=\"http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/222-300x112.png 300w, http:\/\/www.pfsense-br.org\/blog\/wp-content\/uploads\/2012\/01\/222.png 1021w\" alt=\"\" width=\"300\" height=\"112\" \/><\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Pfsense+Squid+SquidGuard logando no Active Directory &nbsp; Na aba \u201cAvailable Packages\u201d procure por \u201csquid\u201d e mande instalar clicando no \u00edcone no canto direito Imediatamente voc\u00ea ser\u00e1 direcionado para a p\u00e1gina do Package Installer, nele veremos o progresso da instala\u00e7\u00e3o do pacote squid e suas depend\u00eancias: Vamos inserir as regras para a rede LAN: OBS.: LAN net [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-31","post","type-post","status-publish","format-standard","hentry","category-pfsense"],"_links":{"self":[{"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=\/wp\/v2\/posts\/31","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=31"}],"version-history":[{"count":1,"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=\/wp\/v2\/posts\/31\/revisions"}],"predecessor-version":[{"id":32,"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=\/wp\/v2\/posts\/31\/revisions\/32"}],"wp:attachment":[{"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=31"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=31"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xaxowareti.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=31"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}