exonetsystems Posted October 6, 2015 Posted October 6, 2015 Hi all, a quick question if I may! I've recently been looking into some sort of hardware appliance that has our SWGfL proxy embedded into it, and passes all network traffic through it. It's an alternative to the transparent proxy system which doesn't seem quite as reliable. Obviously the only frustration with having proxy settings in the first place is the need for BYOD and staff laptops - not too fussed about the devices that never leave school. To look at this from the other end of the spectrum, my question is does anyone have a way of setting the domain clients to use the proxy when they're inside school, but set to go direct when they're outside school? This would have to be without any user intervention, and I want it to work just like any home network when you don't have to worry about proxy settings at all! Thanks in advance
Arthur Posted October 6, 2015 Posted October 6, 2015 does anyone have a way of setting the domain clients to use the proxy when they're inside school, but set to go direct when they're outside school? A wpad.dat is what you need for this.
exonetsystems Posted October 6, 2015 Author Posted October 6, 2015 A wpad.dat is what you need for this. Looks ideal - thanks will have a look into that!
Blue_Cookeh Posted October 20, 2015 Posted October 20, 2015 Guys, Any ideas how this affects things in a DirectAccess environment? I'm looking at deploying a wpad.dat but I don't want staff machines going over DA for Internet access, which is what is going to happen if they pick up the WPAD whilst connected via DA I assume?
deebee Posted October 22, 2015 Posted October 22, 2015 Anything specified by an IPv4 address instead of a hostname will not make it across the DA tunnel given it relies completely on DNS to translate for the DA clients and create an IPv6 NAT64 address to talk to the client with. That's how I make things 'work' for laptops that operate on-site and off-site here. It's a bit dirty but it does work, and is the only way I've found to avoid relying on other things to alter proxy settings, it just silently fails to find the wpad when off-site and goes direct to the internet. Provided your wpad-hosting machine never changes address and is accessible from anywhere on-site, it'll work. Oh how I wish windows supported per-wifi-network proxy settings like iOS and Android have had for years!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now