• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 686
  • Last Modified:

How can I force users to use proxy server, but still have them be able to a home internet connection on their laptop?

Hello,

We are using ISA server 2006 as a proxy server for our network.  We need to force our users to use the proxy server, however we also need them to be able to connect to the internet using their home internet connections as well.  When we lock the setting in the GPO, they cant change it at home, when we unlock it they can choose to bypass the proxy on the local computer.

I know there has to be a way to enforce the use of the proxy.
0
caw01
Asked:
caw01
1 Solution
 
Keith AlabasterEnterprise ArchitectCommented:
You need a business-class device on the outside of ISA that can be configured with access control lists. You would set the acl's to only accept outbound http/https traffic from the ISA server IP address (and other selected source ip's).

If the users then remove the proxy settings then they would access the gateway using their own source IP and the external device would reject the request.

This is quite a common requirement

Keith
0
 
caw01Author Commented:
We found other ways to do this such as auto discovery, but applications that are not auto dioscovery aware bypass the proxy.  At the end of the day, we ended up supernetting our network, moving DHCP to the new range and configured out Cisco ASA not to allow HTTP traffic from that range.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Upgrade your Question Security!

Your question, your audience. Choose who sees your identity—and your question—with question security.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now