Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Client Settings Blocking Mode #1709

Open
regae opened this issue May 20, 2020 · 12 comments · May be fixed by #7738
Open

Client Settings Blocking Mode #1709

regae opened this issue May 20, 2020 · 12 comments · May be fixed by #7738

Comments

@regae
Copy link

regae commented May 20, 2020

dont know if this been asked before,
is this even possible?
blocking mode per client setting?
if so, its a good feature to have

@ameshkov
Copy link
Member

Different blocking mode per client?

@regae
Copy link
Author

regae commented May 20, 2020

yes, that is what meant, sorry for my english

@ameshkov
Copy link
Member

Could you please explain why you would like to have that?

@regae
Copy link
Author

regae commented May 20, 2020

because i’m using pixelserv, so if the client has been installed with pixelserv certificates i’d like to use blockingmode custom ip, for clients that do not have this cert, like friends, i’d like to use blockingmode default.
hope you can understand what i’m trying to say

@Aikatsui
Copy link
Contributor

@ameshkov 🔫 AGH 🤣

@regae
Copy link
Author

regae commented May 20, 2020

@ameshkov 🔫 AGH 🤣

so sad, thought it’d be useful feature
thanks though

@Aikatsui
Copy link
Contributor

Aikatsui commented May 21, 2020

No. for @ameshkov
sorry if you misunderstood :)

@ameshkov
Copy link
Member

@regae

Thanks for the explanation! This makes sense, indeed.

@devinslick
Copy link

Hey @regae , pixelserv-tls is pretty great! I haven't noticed any issues on devices that don't allow me to import the trusted root yet, but I agree that it would be ideal to treat these managed devices differently.

@ameshkov
Copy link
Member

Btw, it makes sense to add something like that to pixelserv-tls: a configurable list of clients where it should try serving HTTPS, for all other clients it can simply reset the connection.

@ishanjain28
Copy link
Contributor

Hi, Another vote for this from me.

I need this feature because I run CA for devices in my homelab but only my devices and a few more have the certificate installed. I would like the blocking mode to be different for clients that have the certificate installed. This way, I can show them a site is blocked page or redirect them to alternatives.

@devinslick
Copy link

Hi, Another vote for this from me.

I need this feature because I run CA for devices in my homelab but only my devices and a few more have the certificate installed. I would like the blocking mode to be different for clients that have the certificate installed. This way, I can show them a site is blocked page or redirect them to alternatives.

This is my exact situation. I had to create multiple AGH instances and setup DHCP (or the AG client) to override DNS on my devices with the CA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

5 participants