Solved

How can I force users to use proxy server, but still have them be able to a home internet connection on their laptop?

Posted on 2008-10-13
2
549 Views
Last Modified: 2012-05-05
Hello,

We are using ISA server 2006 as a proxy server for our network.  We need to force our users to use the proxy server, however we also need them to be able to connect to the internet using their home internet connections as well.  When we lock the setting in the GPO, they cant change it at home, when we unlock it they can choose to bypass the proxy on the local computer.

I know there has to be a way to enforce the use of the proxy.
0
Comment
Question by:caw01
2 Comments
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 500 total points
ID: 22708802
You need a business-class device on the outside of ISA that can be configured with access control lists. You would set the acl's to only accept outbound http/https traffic from the ISA server IP address (and other selected source ip's).

If the users then remove the proxy settings then they would access the gateway using their own source IP and the external device would reject the request.

This is quite a common requirement

Keith
0
 

Author Comment

by:caw01
ID: 22961670
We found other ways to do this such as auto discovery, but applications that are not auto dioscovery aware bypass the proxy.  At the end of the day, we ended up supernetting our network, moving DHCP to the new range and configured out Cisco ASA not to allow HTTP traffic from that range.
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…
Scenerio: You have a server running Server 2003 and have applied a retail pack of Terminal Server Licenses.  You want to change servers or your server has crashed and you need to reapply the Terminal Server Licenses. When you enter the 16-digit lic…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now