Solved

Remove PROXY SERVER references from XP - they keep reappearing

Posted on 2010-08-25
12
470 Views
Last Modified: 2012-05-10
I have removed a proxy server from our environment (Server 2008).  
I have manually deleted the Microsoft ISA firewall client from the machines.
I have removed the PROXY server references from the controlling GPO.
About every 30 minutes the PROXY settings come back alive on the XP machines.
So I set the GPO to cause the PROXY settings to be by machine and not by user. No help.
I have edited the registry for the .DEFAULT USER .   No help.
I'm pretty exhausted after a week of fighting this.  Any help?
0
Comment
Question by:bobzilla51
  • 4
  • 3
  • 2
  • +3
12 Comments
 
LVL 13

Expert Comment

by:Surone1
ID: 33521896
check internet explorer options if it is not automatically discovering proxy servers
0
 
LVL 13

Expert Comment

by:Surone1
ID: 33521921
it's on the connection tab under lan settings
0
 
LVL 20

Accepted Solution

by:
woolnoir earned 250 total points
ID: 33522274
Remove the proxy settings and then run a GPUPDATE /force, if they come back immediately this will tell you the root cause if the application of a GPO.

The next step is to run a report again the machine to test which policies are applying the proxy details,  RSOP (google it).

if it is the policy being applied then at least we know why, and can then start investigating where the application stems from.
0
 
LVL 5

Expert Comment

by:acesover2000
ID: 33522641
Check your DHCP server is not issuing proxy server information.
0
 
LVL 20

Expert Comment

by:woolnoir
ID: 33523794
Let us know your findings :)
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 33523821
There are numerous places that the assignments can be made.

In Group Policy, for example, the setting may have been made in the default domain policy or a new policy could have been created and assigned at a lower OU level.
What is the proxy server you are using - you have placed the question in the ISA-Forefront zone - but you state it is a 2008 server (isa is only supported on Windows 2003) so are you running FTMG or something else completely?

If it is FTMG, open the FTMG Gui, select networking - internal network - properties - web proxy. Make sure FTMG itself is not issuing the settings.

As mentioned above, DNS/DHCP can also be used either through a .pac file or via WPAD. Check your DHCP scopes for a 252 entry. The 252 option is not available by default, it has to be added to even make it available.
0
Too many email signature changes to deal with?

Are you constantly being asked to update your organization's email signatures? Do they take up too much of your time? Wouldn't you love to be able to manage all signatures from one central location, easily design them and deploy them quickly to users. Well, you can!

 

Expert Comment

by:xxndavisxx
ID: 33525706
Check active directory... there is a setting under the users and groups that forces proxy.
0
 
LVL 20

Expert Comment

by:woolnoir
ID: 33529659
Any update on this ?
0
 

Author Comment

by:bobzilla51
ID: 33534180
Our old PROXY server was SURFCONTROL running on a SERVER 2003. I removed all traces of that server, and set the DHCP on S2008 R1 to assign a gateway of a Juniper firewall.  That all seemed to work. I then set the GPO to enforce one PROXY for the machine and not by user.
I don't have a DNS entry for WPAD and I don't have a DHCP 252 entry for PROXY, just our new gateway.

RSOP doesn't show any attempt to modify the PROXY.

What I have found is a setting in the XP registries that may be my culprit.
Here it is (more or less): HKLM\software\microsoft\windows\currentversion\Internet Settings\
  PROXY ENABLE=1
I think I need a quick way to "Force" this registry entry to be ZERO on every XP machine in the AD. Because once I change it to ZERO manually on a machine, it stays that way.

I haven't the experience to do this with a .reg or script or cmd or vb.
I'm am now looking for a quick GPO way to do this (in beween teaching middle school math.) :-)
0
 
LVL 20

Expert Comment

by:woolnoir
ID: 33534239
You can just make a GPO that sets it to 0 ..

Group Policty -> User Configuration -> Windows Settings ->
Internet Explorer Maintenance -> Connection -> Proxy Settings

go there and set no proxy.
0
 

Author Comment

by:bobzilla51
ID: 33534863
Thanks.

That was the first thing we did: we unchecked the PROXY box.  Connection settings are all off; Automatic Browser Configuration is all off; Proxy Settings are all off; User Agent String is blank.  

But GPO doesn't seem to turn it off for those USERIDs that already exist. And for those that already exist, it seems to pop back on.  

Where I've deleted every USERID on the box, turned off PROXY in the machine configuration section of the registry (as I showed above), then PROXY seems to stay off even when the USERID is rebuilt on the XP machine by the server during the users' next LOGON.
0
 

Author Closing Comment

by:bobzilla51
ID: 33541392
Thanks to everyone who contributed to my resolution of this.  :-) The problem is diminished with the help you've given, but it is only eliminated when I remove every user profile from the machine and let them rebuild.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
A procedure for exporting installed hotfix details of remote computers using powershell
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now