indie Posted January 11, 2007 Posted January 11, 2007 I'm sure it's been talked about in here before but I can't seem to find the thread... We run a proxy which all pupils are forced through via the domain group policy, some of the pupils have figured out the old remove network cable at logon trick so the group policy fails but they still get logged on to a desktop. What are the options to get round this? The gateway specified in the IP settings on each machine points to our actual network gateway, I can't change this to a fake gateway as some of the programs on the admin side that we use don't let a proxy be specified so when I change the gateway they suddenly stop working.
Geoff Posted January 11, 2007 Posted January 11, 2007 Either: 1) setup a firewall box of some description. Block port 80 traffic for all clients apart from your admin boxes that need it. 2) alter the default profiles on the pupils machine so that bad things happen when it loads. logoff /y /f as a startup script is probably best.
indie Posted January 11, 2007 Author Posted January 11, 2007 I decided to go with 2. I've added the logoff command to the "run these programs at logon" of the local policy and it works fine. Is there any way to do this to all the machines I want to do this to quickly instead of having to go round each machine editing the policy? When I change the local policy, what does it write to? Can I export it from one machine and drop it onto all the others?
Anddy Posted January 19, 2007 Posted January 19, 2007 Desktop Authority can do this. You don't need to go to each machine - you can perform all operations from one console.
Gatt Posted January 21, 2007 Posted January 21, 2007 Desktop Authority can do this. You don't need to go to each machine - you can perform all operations from one console. :twisted: Desktop Authority - the bane of my life... our LEA use it and its a bloody pain in the arse.. if it doesn't run nothing gets configured, and since our LEA are as close to incompetant as you can get.. it doesn;t run that often...
tom_newton Posted January 22, 2007 Posted January 22, 2007 Option 1) Block all web access except from the proxy - this is good practice anyway, it can prevent things like trojans/unauthorised s/w from operating properly. Done correctly, you can alert on attempted violations, which can help find misbehaving kit...
Geoff Posted January 22, 2007 Posted January 22, 2007 When I change the local policy, what does it write to? Can I export it from one machine and drop it onto all the others? You can do this with a Startup script to manually create the registry keys.
IanB Posted January 22, 2007 Posted January 22, 2007 We found that when the network cable is pulled out, the PC loads the a temporary profile based on the local Default User rather than the assigned mandatory profile. So we copied the logoff script to C:\Documents and Settings\Default User\Start Menu\Programs\Startup\ by GP startup script, and voila! Pull the cable and you get instant logoff. Genuine new users get their profile from the Netlogon share, rather than the local machine, so they don't get the logoff script. I hope this is helpful. ______________________________ Sit vis vobiscum.
tscnmuk Posted January 22, 2007 Posted January 22, 2007 We have all IP's apart from my machine and the proxy blocked on all external communication. This is the best way of doing it in my opinion, fairly bulletproof. Unless they are accessing the internet through the proxy, then they are not accesing the internet at all. Tom
Anddy Posted January 23, 2007 Posted January 23, 2007 Really strange situation. We have no any problems with desktop authority start. Accordingly - all settings are always apply correctly.
Zer0kbps Posted December 17, 2008 Posted December 17, 2008 i remove the default gateway, and add routes for the pain in the a£"$ apps that wont proxy via dhcp static routes. keeps the load of the firewall amongst other things, and stops p2p pretty good
User3204 Posted December 17, 2008 Posted December 17, 2008 Hmm, my default gateway doesn't have a route to the Internet... but if it did, I would setup a filtering rule that allowed staff to see the required IPs but not allow the students to do so. Do you use the same DHCP server on the staff and student networks ?
Azhibberd Posted December 17, 2008 Posted December 17, 2008 Well even though its a very old one.... just to let you know you could just set the GPO to logoff if remote profile isn't found! that way it auto logs you off, just google it you'll find it if not just give me a shout i'll go find exactly where it is
jonathanhaddock Posted December 23, 2008 Posted December 23, 2008 Semi related I guess - proxy avoidance sites, bane of my life, until I stumbled across a student that led me right to a list (and RSS feed) of them: Site: Free Proxy | Unblock MySpace | Facebook Proxy RSS Feed: http://www.1freeproxy.com/feed/atom/ Gets updated fairly regularly and then all you have to do is at the URLs to your proxy URL Block list
tom_newton Posted December 23, 2008 Posted December 23, 2008 Those look to be adding 8-9 proxies/day - good, but when students find a new source you'll have to chase that down too. Got a proxy whitepaper coming out soon - watch this space.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now