corsasport.co.uk
 

Corsa Sport » Message Board » Off Day » Geek Day » group policy to block proxy server use


New Topic

New Poll
  Subscribe | Add to Favourites

You are not logged in and may not post or reply to messages. Please log in or create a new account or mail us about fixing an existing one - register@corsasport.co.uk

There are also many more features available when you are logged in such as private messages, buddy list, location services, post search and more.


Author group policy to block proxy server use
Bart
Member

Registered: 19th Aug 02
Location: Midsomer Norton, Bristol Avon
User status: Offline
28th Feb 08 at 16:36   View User's Profile U2U Member Reply With Quote

Is there a way I could block proxy server use from within an sbs 2003 environment?
Ive already configured the proxy server settings from within IE, but If I was to use proxy software I could access the internet fine.

I think i could do with blocking all HTTP access on all ports except 80.
I only use routing and remote access, no firewall.
Dan Lewis
Member

Registered: 31st Jan 05
Location: Leicestershire
User status: Offline
28th Feb 08 at 16:37   View User's Profile U2U Member Reply With Quote

you can using gpo

define the proxy in the GPO then disable accses to the tools within ie
Bart
Member

Registered: 19th Aug 02
Location: Midsomer Norton, Bristol Avon
User status: Offline
28th Feb 08 at 16:53   View User's Profile U2U Member Reply With Quote

If I dont actually have a proxy (i.e servers connect to internet via the sbs server), theres nothing I can put in there to define a proxy server is there? If i put the servers ip address in there, every webpage will reroute to the servers address.
jamesw
Member

Registered: 28th Jun 02
Location: Station Town, County Durham
User status: Offline
28th Feb 08 at 16:57   View User's Profile U2U Member Reply With Quote

you can disable access to the connections tab in IE via GPO this is how we have done it, infact we have disabled access to most of the IE settings.
Bart
Member

Registered: 19th Aug 02
Location: Midsomer Norton, Bristol Avon
User status: Offline
28th Feb 08 at 17:02   View User's Profile U2U Member Reply With Quote

I have already done this, but a user has installed a proxy at home and is using this (its live from IE) and not remote desktop.
He is also using a fake IP to connect to his machine at home. Its not port 80.

I would have throught on sbs there must be a way to lock down everything on http except port 80?
Dan Lewis
Member

Registered: 31st Jan 05
Location: Leicestershire
User status: Offline
28th Feb 08 at 17:07   View User's Profile U2U Member Reply With Quote

i would go the disipline route tbh if there are things in place to stop it and users are bypassing and find other ways to get pass.
Aaron
Member

Registered: 9th Aug 04
Location: Cottingham, East Riding
User status: Offline
28th Feb 08 at 17:09   View User's Profile U2U Member Reply With Quote

Find out what DynamicDNS name he/she is putting in their browser in order for them to use it as a proxy.

Then, on your own internal DNS, create an entry to send all requests to that URL/IP address to something like http://drivingni.com/design/AccessDenied.jpg

I've done this before
Bart
Member

Registered: 19th Aug 02
Location: Midsomer Norton, Bristol Avon
User status: Offline
28th Feb 08 at 17:13   View User's Profile U2U Member Reply With Quote

the trouble is he sat at his pc all the time. Theres no easy way for me to find this.
Aaron
Member

Registered: 9th Aug 04
Location: Cottingham, East Riding
User status: Offline
28th Feb 08 at 17:14   View User's Profile U2U Member Reply With Quote

can you not check his IE history or use VNC?
Bart
Member

Registered: 19th Aug 02
Location: Midsomer Norton, Bristol Avon
User status: Offline
28th Feb 08 at 18:05   View User's Profile U2U Member Reply With Quote

ive never tried using VNC before.
Is it part of Small business server or just windows 2003 full?
Aaron
Member

Registered: 9th Aug 04
Location: Cottingham, East Riding
User status: Offline
28th Feb 08 at 18:27   View User's Profile U2U Member Reply With Quote

VNC is a small open source desktop sharing application.

Google for Real VNC. Then install it on his computer. You'll need to instal the viewer (part of the main .exe which you'll download) to view his screen.

Easy
Bart
Member

Registered: 19th Aug 02
Location: Midsomer Norton, Bristol Avon
User status: Offline
28th Feb 08 at 18:40   View User's Profile U2U Member Reply With Quote

yes, but a little disheartening to the people to have go and install VNC on their machines
Aaron
Member

Registered: 9th Aug 04
Location: Cottingham, East Riding
User status: Offline
28th Feb 08 at 18:50   View User's Profile U2U Member Reply With Quote

Your call then mate, can't do much more for ya.
MikeD
Member

Registered: 18th Aug 02
Location: Whittlesey, Cambridgeshire
User status: Offline
28th Feb 08 at 19:55   View User's Profile U2U Member Reply With Quote

so he has installed software on his home machine for a proxy? whats the software? and what port is he going out on?
Bart
Member

Registered: 19th Aug 02
Location: Midsomer Norton, Bristol Avon
User status: Offline
29th Feb 08 at 07:06   View User's Profile U2U Member Reply With Quote

that im not sure of.Im just trying to see if i can log access on the draytek 2800.
Bart
Member

Registered: 19th Aug 02
Location: Midsomer Norton, Bristol Avon
User status: Offline
29th Feb 08 at 08:01   View User's Profile U2U Member Reply With Quote

Ive a feeling this is being used: http://www.wampserver.com/en/index.php
Bart
Member

Registered: 19th Aug 02
Location: Midsomer Norton, Bristol Avon
User status: Offline
3rd Mar 08 at 11:48   View User's Profile U2U Member Reply With Quote

https://www.proxify.com is whats being used.

I think its because its https is why i cant block it. Any ideas?

 
New Topic

New Poll

  Related Threads Author Forum Replies Views Last Post
Network boffs (Software).....Bit of help with my setup Aaron Geek Day 8 1101
18th Dec 05 at 00:01
by Aj.
 
Security policy re IE Melville Geek Day 3 761
3rd Nov 06 at 16:17
by PaulW
 
help me block someone whos using a proxy website Bart Geek Day 26 2034
26th Mar 07 at 15:18
by loafofbrett
 
Urgent solution required..... Richie Geek Day 0 943
11th May 07 at 09:57
by Richie
 
I.P. re-routing. Tiger Geek Day 2 502
26th Jan 08 at 18:52
by kz
 

Corsa Sport » Message Board » Off Day » Geek Day » group policy to block proxy server use 28 database queries in 0.0159540 seconds