Solved

active directory 2003 organizational units

Posted on 2011-03-15
6
332 Views
Last Modified: 2012-05-11
i have an active directory domain - with windows 2003 servers. i have a few organizational units with different group policies. now i need to have everyone go through my squid proxy server. i want the laptop users to use the proxy in the domain, but not when they are traveling. is there a way to do this?
0
Comment
Question by:JeffBeall
  • 3
  • 2
6 Comments
 
LVL 31

Expert Comment

by:Justin Owens
ID: 35139119
Not really.  You can set a top level GPO to set your proxy server for all your OUs easily enough.  What you CAN do is have your laptops in a different OU and not enforce it there, that way they can change the setting manually.  When the come back to the office, it will revert (GPO Allies again), but when they leave, they can change it to none.  That is how we accomplish it at my current location.

DrUltima
0
 
LVL 1

Author Comment

by:JeffBeall
ID: 35139194
i'm not concerned with getting the policy out to everyone - i'm more concerned with laptop users not going through the proxy outside the domain.
0
 
LVL 1

Author Comment

by:JeffBeall
ID: 35139222
i just had a thought - i could have an OU for laptops that doesn't have the proxy policy - then through their login script - make it so they use the proxy.
only problem is i don't know how to script. the current login "script" is a simple batch file that sets up the network shares.
would this be possible?
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 31

Accepted Solution

by:
Justin Owens earned 250 total points
ID: 35139349
Yes, but to make it transparent to the end user, you would also need a log off script to turn the proxy back off.  Batch itself cannot do it, but it can import registry settings which can:

http://www.experts-exchange.com/Programming/System/Windows__Programming/Q_21069499.html

This Question details how to accomplish through Batch registry manipulation.
0
 
LVL 5

Assisted Solution

by:xylog
xylog earned 250 total points
ID: 35143812
You can set your browsers to autodetect and use WPAD -> http://en.wikipedia.org/wiki/Web_Proxy_Autodiscovery_Protocol Either using a DNS entry called wpad or a DHCP option. When off the network they will not resolve the DNS entry or have the DHCP setting so they will autodetect the lack of a proxy and directly access the net. WPAD is supported in Firefox also.
0
 
LVL 1

Author Closing Comment

by:JeffBeall
ID: 35180617
thank you
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Synchronize a new Active Directory domain with an existing Office 365 tenant
Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question