Ask Experts Questions for FREE Help !
Ask
    ashley velez's Avatar
    ashley velez Posts: 67, Reputation: 1
    Junior Member
     
    #1

    Mar 17, 2009, 11:39 AM
    Internet Explorer Exceptions Group Policy
    We are setting up a proxy server at my work. We want to set a group policy so they must connect to it. Problem is, we connect to a lot of VPN's a local sites. When you go to internet options-> connections->lan settings-> advanced, there is an exception box. (First of all, when you click bypass proxy for local intranet, it doesn't bypass) So anyway we have a lot of characters in the exceptions. I guess in IE7 you can only have 250 characters in the exception box, (Most users here have IE7) but in IE6 you can have up to 1024 characters. Well our domain controller where we'd set up the GPO is using IE6... If I set the GPO with the proxy rule and added the exceptions, would it still work on the people with t IE7?
    chuckhole's Avatar
    chuckhole Posts: 850, Reputation: 45
    Senior Member
     
    #2

    Mar 17, 2009, 11:50 AM

    Question: What proxy server are you using? Does it support Windows Proxy Auto Discovery (WPAD)?

    Your exceptions list is for domains so it should be a short list and does not include any protocol specifics (no http, etc.).

    I would highly suggest using the custom DHCP 252 WPAD entry to autoconfigure your clients. Then, you can set your IE6 and IE7 clients to "Automatically detect settings" so that it will NOT make it difficult for your mobile users.

    You can then set your GPO to push out this setting instead of the problematic proxy server settings.
    ashley velez's Avatar
    ashley velez Posts: 67, Reputation: 1
    Junior Member
     
    #3

    Mar 17, 2009, 11:56 AM
    The proxy server is safe-squid for linux, but every other computer is part of a WIN AD domain.
    chuckhole's Avatar
    chuckhole Posts: 850, Reputation: 45
    Senior Member
     
    #4

    Mar 17, 2009, 12:28 PM
    Quote Originally Posted by ashley velez View Post
    The proxy server is safe-squid for linux, but every other computer is part of a WIN AD domain.
    It is good that it is an AD Domain. You have DNS and DHCP to work with as well as a central security authority for your proxy rules.

    Follow the related information at Content Filtering - client-side to set up your custom PAC/DAT file. You can then add the custom DHCP with the help of Configuring Automatic Discovery for ISA Server Clients.. It is for the Microsoft ISA Server community but the DHCP configuration is the same. Rename your PAC file to WPAD.DAT to conform to the DHCP requirements. Try not to use the DNS configuration if you have multiple AD sites or DNS domains.

    Lastly, to setup your proxy server as your DNS forwarder, you will need to install DNS on your proxy server without any primary zones so that it can cache your requests. Then add your AD DNS as a Secondary Zone. In your DNS configuration on your proxy server, add your ISP DNS servers as the forwarders. Set your public NIC IP properties with no DNS and your LAN NIC IP properties to itself as the primary DNS server.

    Then in your AD DNS configuration, add your Proxy server DNS address as a name server and add this as your forwarder for all other DNS domains. Your internal clients will first go to your internal DNS and then your internal DNS will forward the request to your Proxy DNS which caches the results that it retrieves from your ISP DNS. Subsequent requests within the TTL will be performed locally from the cache.

    Your DHCP server will automatically configure your clients for DNS and WPAD prior to logon and your single configuration will also serve you well for your mobile clients.

Not your question? Ask your question View similar questions

 

Question Tools Search this Question
Search this Question:

Advanced Search

Add your answer here.


Check out some similar questions!

How to use Group Policy to block user internet downloading? [ 15 Answers ]

I have a computer for my kid, the OS is XP professional, I create only one administrator account for him(for my personal reason, I want my kid use administrator account only, not limited account, not other accounts). I allow my kid to access internet, but I don't want my kid downloading any...

Firewall LOCKED by Windows Group Policy? Can't get on Internet! [ 2 Answers ]

My dad recently gave me his old work laptop that he used at the college which he worked at... I have been trying to get on the internet at home, however, I'm only able to find the wireless connection, (no internet). I looked at the firewall settings and since the computer was under the "Windows...

Group Policy settings [ 1 Answers ]

How do I prevent all users in a site to not be able to change the desktop background and screen saver?

Difference between domain group policy and DC policy? [ 1 Answers ]

Hi all, may I know the difference between domain group policy and domain controller policy. If I want to restrict a user who is accessing the local drives and CD drive of a client machine and internet. How can I prevent the user/user. Thanks varughese abraham.

Local group policy [ 1 Answers ]

How can I restrict local users by using group policy. I want to create a user and allow them to use .NET and SQL Server. The local user should be a member of which group?


View more questions Search