actech Posted October 11, 2009 Posted October 11, 2009 Hi, We run ISA 2006 mainly because our webfilter (SurfControl) sits on it. At the moment it allows authenticated users (integrated) through only. What I am would like is to allow staff members to hook up their laptops to the network wihtou having to connect to the domain and authenticate with their domain usr & pwd to get internet access. Is this possible and how? I have tried setting basic authentication to no avail and also using the 'run as' with IE7 with no luck. All help appreciated.
EduTech Posted October 11, 2009 Posted October 11, 2009 So are you asking how you can get staff to use the ISA as there gateway to the internet internally? if so then you will need to set there proxy in IE as the ISA Server's IP Address. Setup a rule to allow internal traffic to external If you need any help feel free to PM me and i can forward you over some rules to try James.
timzim Posted October 11, 2009 Posted October 11, 2009 Their laptops will have to pick up an ip from your network's dhcp which should also set the laptop's gateway to the proxy's address (if you've got dhcp set up right). In IE / Tools / Internet Options / Connections / LAN Settings either choose Automatically Detect Settings or, if that doesn't work (needs setting up a few things on the ISA server first), instead enter in the lower section the network name of your proxy server and the port it uses (probably 8080). Your current rule should let your users through since they're authenticating using their network username/password, although they might need to type the domain name as well, e.g. DOMAIN\username in the username box.
EduTech Posted October 11, 2009 Posted October 11, 2009 Your current rule should let your users through since they're authenticating using their network username/password, although they might need to type the domain name as well, e.g. DOMAIN\username in the username box. Users locally will not have to authenticate again, ISA should automatically allow them through depending on how the rule is setup.. if you allow all users then any one internally can pass through... if you only want specific users to be allowed access, then you will need to create a group with a security group from AD selected and only allow that group through rather than all users.
actech Posted October 11, 2009 Author Posted October 11, 2009 The DHCP sets the ISA server as the gateway, but I just thought I have it set as a proxy on 8080. This won't automatically be configured will it? I have a feeling that the GPO for the proxy is set via user not machine. Will have to wait till I get to work to check this out.
EduTech Posted October 11, 2009 Posted October 11, 2009 If IE is set to automatically find the settings, and ISA is configured to do so then yes it will work... if not then you will either need to change the settings on ISA or set the proxy via GPO in User Settings. ISA server firewall,proxy,superNAT settings < that should help to configure ISA so IE picks up settings. James. 1
bio Posted October 12, 2009 Posted October 12, 2009 I would create a seperate subnet ( and use DHCP) for these laptops. Then create a new firewall rule that allows internet from this subnet to external without authentication. Place this rule above your normal internet rule regards bio..
timzim Posted October 12, 2009 Posted October 12, 2009 I think the actec's original rule is more secure since it only allows authenticated users (eliminates anyone hacking the network/stealing your bandwidth). His/her users will still have to authenticate with username/pw because he/she's only allowing authenticated users. Works successfully like this on our network. Setting proxy values in GPO will have no effect since user's not actually logging on when authenticating, i.e. won't be loading any profile so no GPO's applied, so will need set proxy details in browser settings (as I said earlier....zzzzz). 1
actech Posted October 12, 2009 Author Posted October 12, 2009 Thanks all for the replies. It was to do with configuring the proxy settings on ISA and within IE7. Bio - I did have it like but the boss told me to shut it down and teachers were looking at inappropriate material around students so all traffic now has to go through the filter. I have done up a cheat sheet for staff to show them how to change settings. If they can't be bothered learning then they don't get access. Simple as that!
timzim Posted October 12, 2009 Posted October 12, 2009 teachers were looking at inappropriate material around students Grounds for dismissal here. Get yourself an AUP!
actech Posted October 12, 2009 Author Posted October 12, 2009 Not quite dismissal. The event that sparked it was a teacher was checking emails while supervising a study group. He got one of those joke ads for Durex and several students overheard it. While it was just a joke and a legit ad, one of the students told their parents (who just happen to be on the school board) who complained to the Head. It was a case of sh!t happens but we are now making sure that it can't again.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now