Primary Domain Controller (PDC) with Open Ldap and Squid

I have a network with 5 Lan. They are:
Lan Test 192.168.98.X;
Lan Administration 192.168.10.X;
Lan Laboratoy 192.168.97.X;
Lan Wireless 192.168.95.X
Lan PDC 192.168.96.X

My Layout Network is:
http://picasaweb.google.com/105817325367668946893/LinuxForum#5502353140415862434

I must authenticate the request access and use of internet (mail, browser, ecc…) of user lan: Administration 192.168.10.X, Laboratory 192.168.97.X and Wireless 192.168.95.x from lan PDC/PROXY (192.18.96.10).
The user of lan test (192.168.98.X) must not use the nas (192.168.92.20) and PDC/PROXY (192.168.96.10)

What instruction i must insert to firewall mikrotik ?

Tank’s

dst-nat all http requests to PDC, Squid should do authentication

and the request of autentication from computer client with domain ?

I mean, RouterOS WebProxy cannot authenticate users (well, HotSpot can, if you can use it). if you use Squid - let it authenticate. it has nothing to do with RouterOS