home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.novell
- Path: sparky!uunet!ukma!darwin.sura.net!sgiblab!newsun!dseeman
- From: dseeman@novell.com (Daniel Seeman)
- Subject: Re: Hiding Macs from other zone users
- Message-ID: <1992Nov18.210655.3417@novell.com>
- Sender: news@novell.com (The Netnews Manager)
- Nntp-Posting-Host: db.sjf.novell.com
- Organization: Novell Inc., San Jose, Califonia
- References: <Tony.McDonald-181192124447@launchy.ncl.ac.uk>
- Date: Wed, 18 Nov 1992 21:06:55 GMT
- Lines: 45
-
- In article <Tony.McDonald-181192124447@launchy.ncl.ac.uk> unregistered@newcastle.ac.uk (Tony McDonald) writes:
- >Hello,
- >We have a server with two ethernet cards. One card is connected to the
- >campus ethernet, the other onto a small 'leg' that has 14 Macs attached to
- >it.
- >
- >We want to prevent the 'leg' macs from seeing any AppleTalk traffic from
- >the campus in general, and to stop our users on the 'leg' side from
- >printing to any of the other printers that are available on campus.
- >
- >Does anyone have any clues as to how this may be achieved.
- >The first priority is to prevent AppleTalk traffic from emanating from this
- >'leg'. Stopping printing is also necessary, but we beleive that Novell can
- >handle this adequately.
- >
- >Any and all help will be appreciated.
-
- Hi,
-
- Unbind AppleTlk from the "Leg's" ethernet interface. Then, install a NetWare
- Router (Routegen is bundled with the OS, I think). You will then install and
- configure the VAPs (NetWare for Macintosh Value Added Processes v2.x) to be
- loaded on top of ROUTER.EXE. Subsequently, the "Leg" Macintoshes will see only
- the file server which is targeted by the VAPs. Furthermore, no AppleTalk
- traffic will be passed between the two ethernet NICs in the 3.11 server.
-
- Print services will be handled in much the same way as the file services when
- using the VAPs.
-
- Hope this helps. Let me know if it does not.
-
- Think Peace...
-
- Dan Seeman
- Novell
- Walnut Creek, Ca.
-
- PS. Keep your eyes open in the near future for a more elegant solution to this
- problem. But realize as well that currently there is PLENTY of security flex-
- iblity to offer very similar functionality. No user can login to a server on
- which she has no rights. No user can use a queue unless he is a queue user.
- You may want to investigate the power of security before using the rather brute
- force functionality provided by the VAPs.
-
-
-