>> > 3. Also i need a reject rule for those users, who was authenticated by LDAP and do not belong to any ldap-group. I've tried Ldap-Group !*, but this attribute always exists for every user :( Try unlang: if (!control:Ldap-Group) { ... Ivan Kalik Kalik Informatika ISP