EFW Support

Support => EFW SMTP, HTTP, SIP, FTP Proxy Support => Topic started by: ryanpg on Friday 10 December 2010, 04:35:42 am



Title: Log Username in Dansguardian accesss.log AND have Multiple Filter Groups
Post by: ryanpg on Friday 10 December 2010, 04:35:42 am
Hi all. I'm a tech coordinator for a small school. Currently, I'm using Endian Firewall Community Edition 2.4.1 to provide a non-tranparent proxy (users are divided into three groups, students, teachers, administrators), content filtering, etc.

With previous releases of EFW, I've been able to "hack" support for displaying usernames in the DG logs, i.e. when someone visits a denied site, their name is logged along with the site.

With the current version, the default authentication plugin for DG has been changed to IP authentication. Presumably, to allow for multiple filter groups. The VERY unfortunate side-effect being the loss of usernames appearing in DG logs.

Ugh.

A few ssh sessions and through some exploration, I realized that by changing the auth plugin method in /etc/dansguardian/dansguardian.conf (and the .tmpl file too) to proxy-basic, I was able to regain logged usernames. Aaaand... lose multiple filter groups.

So, are these two options: multiple filter groups AND logged user names really mutually exclusive? If so, that's very frustrating and annoying - not to mention quite limiting and time consuming in a school setting.

If not, could some kind soul please clue me in, and explain how I can maintain multiple filter groups AND have usernames appear in the DG log files?

Thanks much,
Ryan