Re: Need assistance with enforcing internet ACL (when users can install firefox)

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



pez wrote:
We control access to the internet though an ISA server (which works
fine). To get to the internet users use a proxy (which is the ISA
server). But some have figured out that if they install firefox by
default it connects them directly to the gateway (bypassing the ISA
box). Because of other applications users need to have local admin
rights so even if I remove firefox, they can just reinstall. Anyone
have any suggestions?


Absolutely. There are a couple of ways that you could handle this.

The first would be to find where the proxy settings for Firefox are stored and make changes to those pro grammatically (registry, etc.)

That's not an ideal solution, though, because as soon as you do that they'll install Opera, then Safari, then something else.

The best way to handle this would be to create Access Control Lists on your gateway itself that only allow the ISA server to access the internet. You could also add entries for servers, etc. Hopefully you have them on a different LAN segment so this would be easy to do.

This way, you are able to prevent the users from accessing the internet unless they go through the proxy, regardless of which application they are using.


--

Jack Doyle, Systems Engineer
ScriptLogic Corporation
http://www.scriptlogic.com
.



Relevant Pages

  • Re: ISA 2004 & companyweb
    ... Server, the traffic will still be handled by the ISA Server because the ... "Bypass proxy server for local addresses" option is disabled, ...
    (microsoft.public.windows.server.sbs)
  • Re: Firefox ermöglicht Zugriff zu allen Seiten des Internets
    ... > einen Windows 2000 Server mit ISA Server ins Internet. ... > Installation von Firefox. ... Ist bei dem Firefox der ISA-Server als Proxy eingetragen? ...
    (microsoft.public.de.security.netzwerk.sicherheit)
  • Re: ISA server 2004 and Bluecoat proxy
    ... i want to mention that we have configured a backup rout (backup bluecoat ... i want to ask about event 14130 that related to web proxy chain fauilire. ... If you were able to work around the upstream proxy server, ... upstream ISA Server, you might want to change it back. ...
    (microsoft.public.isa.configuration)
  • RE: Proxy Server in SBS 2000
    ... sites through port 443. ... If you install ISA 2000 on the SBS 2000 server, ... Connections->LAN Settings, tick the Use proxy server for your LAN, and then ... Is ISA 2000 installed on the SBS Server? ...
    (microsoft.public.windows.server.sbs)
  • Poor client web browsing performance
    ... I've switched all our users from an old proxy 2.0 server to ISA 2004, ... That DNS server is configured with the ISA server's internal NIC ... The first firewall policy rule is called "unrestricted internet ...
    (microsoft.public.isa.configuration)