MkII Posted April 5, 2006 Posted April 5, 2006 I was experimenting with censornet over the weekend, and changed the GPO proxy settings to point to the censornet box. Took a little fiddling to get it going, finally blanking the local profile proxy settings did the trick. Changed it back, and no machines were picking up the correct proxy and getting out to the web! Setting a local proxy again has fixed it for the kids, but staff are still unable to get out. Staff are on a child domain and no settings were changed there!
Quackers Posted April 5, 2006 Posted April 5, 2006 Are they Windows XP Service Pack 2 clients? As Service Pack 2 broke the GPO for Proxy Settings and they do not get applied. Cannot find the support artical now, but i had this problem last year and found SP2 to be the cause.
MkII Posted April 5, 2006 Author Posted April 5, 2006 Not all SP2 - the vast majority, but I have one Win2K with the problem. I'll go play with that one and see if I can't get it going.
MkII Posted April 5, 2006 Author Posted April 5, 2006 On the XP SP2 PCs: Turned on the LAN settings page for staff users and they have auto detect settings checked and no proxy set [with the censornet address greyed out]. Firewall is off on this PC as I read proxy settings maybe affected by that. Still no closer
NetworkGeezer Posted April 5, 2006 Posted April 5, 2006 It might be something to do with the GPO caching. In order to speed up XP booot times I think MS have made it so that GPO changes to clients are only applied after a reboot. Anyway as a possible workaround have you tried setting the proxy value in the DHCP options?
Quackers Posted April 5, 2006 Posted April 5, 2006 Do you have folder redirection on the same policy as internet explorers maintence settings? I can find this artical which says in SP2 Computers with folder redirection and IE's settings in , the folder redirection fails. http://support.microsoft.com/default.aspx?scid=kb;en-us;888254 Its not the fix your after, but i found my PC's did the reverse, IE's settings failed and folder redirection worked. Do you have any SP1 machines you can test this on just to confirm its somthing MS have messed so SP2 broke it? If its the problem i had you'll find no SP and SP1 machines do as you expect. This person has the same problem http://groups.google.co.uk/group/microsoft.public.windows.group_policy/browse_thread/thread/152005cadb5a7850/64cbdc02315ee225?lnk=st&q=internet+explorer+proxy+not+applied+windows+xp&rnum=1&hl=en#64cbdc02315ee225 it was Application Data redirection on the same group policy that was the problem.
MkII Posted April 5, 2006 Author Posted April 5, 2006 Thanks for those guys :goes off to investigate: @Networkgeezer: How do you set proxy values in DHCP? @Quackers: Yes - folder re-direction happens on the same policy [i also re-direct an applications' settings too on that GPO]
Netman Posted April 5, 2006 Posted April 5, 2006 Thanks for those guys :goes off to investigate: @Networkgeezer: How do you set proxy values in DHCP? You need to set up wpad (web proxy auto-detection protocol) if your proxy supports it... you can use either dns or dhcp to do this... further info for using ISA2004 and wpad is here http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/automaticdiscovery.mspx In DHCP you need to add a 252 wpad option and insert the url of your proxy wpad file... eg. "http://cerberus:80/wpad.dat"
Michael Posted April 5, 2006 Posted April 5, 2006 To my knowledge Windows 2000 Server, Server 2003 and XP Pro update their policies every 90 minutes. I would recommend specifying the proxy settings from the MMC console (using XP). Start > Run > MMC and add the Group Policy Object Editor. Specify the Active Directory Group Policy Object, then specify your proxy settings. Now click Start, Run and type gpupdate A command prompt will appear and then disappear once complete. Now open up IE and check whether your proxy settings have been applied.
MkII Posted April 5, 2006 Author Posted April 5, 2006 OK. Win2K PC exactly the same - no joy. Tried moving proxy setting to a seperate OU. Also removed Appication Data re-direction. Results of policy wixard say that policies are bieng applied - but to same admin user actually logged into the machine at the same time the evidence shows the policies didn't apply. @Netman: Our proxy server is a slackware linux box - i'll ask if that'll support wpad. Looking into scripting proxy setting via kixtart.
Geoff Posted April 5, 2006 Posted April 5, 2006 i'll ask if that'll support wpad Quite easy to do, I've played with it in the past. All you need is a webserver and the right DNS entries.
Ric_ Posted April 5, 2006 Posted April 5, 2006 I've had Windows XP boxes have wiered proxy problems before now, where the IE settings are right but the rest of Windows throws a wobbler and things like Windows Update don't work. There is a command called 'proxycfg' that allows you to reset the proxy settings - this generally works for me. http://support.microsoft.com/default.aspx?scid=kb;en-us;830605 has a few details. It states that it is available for Win2K SP4 too.
MkII Posted April 5, 2006 Author Posted April 5, 2006 Interesting Ric. Didn't seem to do anything! Sorted my problem anyway - found the GPO that was calling the shots - the Computer OU. Definately changing to an alternate method, either scripted or server out by DHCP. Thanks everyone for your help
NetworkGeezer Posted April 5, 2006 Posted April 5, 2006 @Ric_: I think ProxyCfg only sets the proxy value used by automatic updates @Mark: Glad it worked out. How did you find the culprit, cleitns side diagnostics or did you simply stare the problem into submission
MkII Posted April 10, 2006 Author Posted April 10, 2006 More of the staring type diagnostics Geezer! - though as usual - some overnight contemplation helped greatly.
Geoff Posted April 10, 2006 Posted April 10, 2006 I think ProxyCfg only sets the proxy value used by automatic updates Nearly, it sets the proxy for WinHTTP. Where as the older versions used the IE settings the new WinHTTP requires you specifically tell it whats going on. I use the following setting proxycfg -d -p proxy.mynetwork.net:8080 mywsusserver Which means that Windows Updates still works yet I can use WSUS without clients failing to find the server. WinHTTP is also used for Windows Defender definition updates too btw. Glad it worked out. How did you find the culprit, cleitns side diagnostics or did you simply stare the problem into submission The GPMC will help you here.
NetworkGeezer Posted April 10, 2006 Posted April 10, 2006 Gosh, I didn't realise I made such a hash of spelling the word 'clients'. :oops: Obviously a lot of you must do the Times crossword
NetworkGeezer Posted April 10, 2006 Posted April 10, 2006 proxycfg -d -p proxy.mynetwork.net:8080 mywsusserver Which means that Windows Updates still works yet I can use WSUS without clients failing to find the server. Windows Update doesn't need a proxy value set by proxyfg. Automatic Updates does.
Geoff Posted April 10, 2006 Posted April 10, 2006 Both use WinHTTP. But so does WSUS. So you have to get it just right. If you don't believe me, ask it whats happening with BITSAdmin.exe.
NetworkGeezer Posted April 10, 2006 Posted April 10, 2006 Well WinHTTP must revert to it's old behaviour of using the IE proxy value in HKCU because I have run on WU sucessfully several times without bothering with proxycfg. Automatic updates, however, has always needed proxycfg -u or -p to be run.
Geoff Posted April 10, 2006 Posted April 10, 2006 It does work to a point. It just gets stuck forever trying to download updates direct instead of going via a proxy.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now