Jump to content

Recommended Posts

Posted

I'm sure it's been talked about in here before but I can't seem to find the thread...

 

We run a proxy which all pupils are forced through via the domain group policy, some of the pupils have figured out the old remove network cable at logon trick so the group policy fails but they still get logged on to a desktop.

 

What are the options to get round this? The gateway specified in the IP settings on each machine points to our actual network gateway, I can't change this to a fake gateway as some of the programs on the admin side that we use don't let a proxy be specified so when I change the gateway they suddenly stop working.

Posted

Either:

 

1) setup a firewall box of some description. Block port 80 traffic for all clients apart from your admin boxes that need it.

 

2) alter the default profiles on the pupils machine so that bad things happen when it loads.

 

logoff /y /f

 

as a startup script is probably best.

Posted

I decided to go with 2. I've added the logoff command to the "run these programs at logon" of the local policy and it works fine. Is there any way to do this to all the machines I want to do this to quickly instead of having to go round each machine editing the policy?

 

When I change the local policy, what does it write to? Can I export it from one machine and drop it onto all the others?

Posted
Desktop Authority can do this. You don't need to go to each machine - you can perform all operations from one console.

 

:twisted: Desktop Authority - the bane of my life... our LEA use it and its a bloody pain in the arse.. if it doesn't run nothing gets configured, and since our LEA are as close to incompetant as you can get.. it doesn;t run that often...

Posted
Option 1) Block all web access except from the proxy - this is good practice anyway, it can prevent things like trojans/unauthorised s/w from operating properly. Done correctly, you can alert on attempted violations, which can help find misbehaving kit...
Posted
When I change the local policy, what does it write to? Can I export it from one machine and drop it onto all the others?

 

You can do this with a Startup script to manually create the registry keys.

Posted

We found that when the network cable is pulled out, the PC loads the a temporary profile based on the local Default User rather than the assigned mandatory profile. So we copied the logoff script to C:\Documents and Settings\Default User\Start Menu\Programs\Startup\ by GP startup script, and voila! Pull the cable and you get instant logoff.

Genuine new users get their profile from the Netlogon share, rather than the local machine, so they don't get the logoff script.

I hope this is helpful.

 

______________________________

 

Sit vis vobiscum.

Posted

We have all IP's apart from my machine and the proxy blocked on all external communication. This is the best way of doing it in my opinion, fairly bulletproof. Unless they are accessing the internet through the proxy, then they are not accesing the internet at all.

 

Tom

Posted
Really strange situation. We have no any problems with desktop authority start. Accordingly - all settings are always apply correctly.
  • 1 year later...
Posted

i remove the default gateway, and add routes for the pain in the a£"$ apps that wont proxy via dhcp static routes.

 

keeps the load of the firewall amongst other things, and stops p2p pretty good

Posted

Hmm, my default gateway doesn't have a route to the Internet... but if it did, I would setup a filtering rule that allowed staff to see the required IPs but not allow the students to do so.

 

Do you use the same DHCP server on the staff and student networks ?

Posted
Well even though its a very old one.... just to let you know you could just set the GPO to logoff if remote profile isn't found! that way it auto logs you off, just google it you'll find it if not just give me a shout i'll go find exactly where it is
Posted

Those look to be adding 8-9 proxies/day - good, but when students find a new source you'll have to chase that down too.

 

Got a proxy whitepaper coming out soon - watch this space.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...