Hello to all,
we use Confluence as a self hosted server in a DMZ.
It's possible to Access the Server from Intranet and Internet.
At this Moment we disabled the anonymous Access. We don't want that the Content is accessable for all.
We have some spaces we want to make read only for everyone in our Company.
This anonymous Access should only work if you open the System from our Company lan.
If you are an user from the Internet a Login must be required.
How can we realise this?
image2016-8-30 10:3:24.png
Confluence does not allow different security settings based on where you visit it from.
Assuming you have someone quite technical there and use windows you could set up a local bounce box, which authenticates using SSO using Oauth via NTLM, which would automatically log the user in and allow full read only access, restricted based on if a user is logged in or not. This would additionally allow users to login externally and work from home.
The Problem is, that we are a large company. We don't want to buy so much licenses at this moment. So all users without an account should have anonymous rights without obtaining an extra license
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Maximilian,
you had a great idea I want to use but I have no idea how to set this up.
Any tipps?
Julia
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
What do you think about this idea:
Use a Apache Reverse Proxy. Identify if the traffic comes from Internet or Intranet.
If traffic source is Intranet: Allow full access
If traffic source is Internet: Check if User has a Confluence Session ID. If not Redirect to loginpage. Deny all Pages if user has no cookie
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Maximilian,
you had a great idea I want to use but I have no idea how to set this up.
Any tipps?
Julia
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.