Jump to content

Recommended Posts

Posted

I'm trying and failing miserably so I turn you my fellow edugeekers help point me in the right direction and to tell me what the heck I am doing wrong!!

 

I am trying to setup Loopback processing (Merge) for my Terminal Servers.

 

Created a GPO to enable loopback processing in Merge mode. That is the only setting in that GPO and it is applied to the OU where my Terminal Server is located. The security filtering is set to Authenticated Users.

 

Created another single GPO with a different proxy setting for IE and linked it to the OU where the TS is located. Security set for Authenticated users.

 

 

To me, that should work - shouldn't it?

 

Ran through the Modeling Wizard, Selected my users OU and my TS OU - looked at the results and it shows my TS Proxy Setting as the winning GPO for the proxy settings.

 

Ran the Result Wizard, selected my TS and my test account - looked at the results and - my Global IE Proxy setting wins over the TS Proxy setting.

 

 

So.... what am I doing wrong/missing?

 

Cheers

Mark

Posted

You should have the proxy setting for the users and the the user loopback processing (on Merge) in the same GPO.

 

You are applying a user settings to an OU that contains only computers (not users), therefore you need the GPOs in there to have loopback on. You can also set them to enforced should you wish, to make sure it has priority.

 

 

However, I assume this is related to your other question to Smoothwall about authenication methods, which would be why you are wanting two different proxies, one affecting users generally and one on just these machines. You shouldn't need to have two different types of authenication, and as such you shouldn't need a different proxy

  • Thanks 1
Posted

Thanks Adrian, makes sense about the loopback settings.

 

Tried setting all to use NTLM for everyone but had issues with Smoothwall not seeing/using all usernames and so classing some as unauthenticated IPs - were as IdentD works fine.

 

Downside is IdentD doesnt work well with Terminal Servers as it uses the same username for all users.

 

Smoothwall wont allow me to use two different authentication methods using the same port which is why I was trying to get the TS to use a different proxy port.

 

Hope that makes sense.....

 

Cheers

Mark

Posted

If thats the case then put the both the loopback processing and the proxy settings within one policy, linked to the Terminal Services OU and enforce it. If it doesn't work then gpresult or rsop it and find out which has applied (or hasn't).

 

Also dobule check that the Terminal Services profile hasn't got proxy settings in because they can cause problems.

 

 

Personally I would move to something like Kerberos (Terminal Services Compatibility Mode), it also works with iMacs. As that definitely works on Terminal Services, Windows Clients and iMacs and will only mean you have 1 policy to maintain.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...