On Jul 24, 2011 2:34 PM, "Andrew Miehs" <[email protected]> wrote:
>
> And this works? If the users can change their proxy settings, they can
normally change
> c:\windows\system32\etc\hosts (or whatever the file is called).
>
> The only solution we have found that really works is not allowing clients
directly into the
> Internet. All traffic must traverse the DMZ. If they want http, they need
to use the HTTP
> proxy that we provide them - not that they have much choice - group
policies, etc.

Yes, the default gateway for the clients where Linux boxes running iptables
with squid and squidGuard, acting as transparent proxies, you had no choice
but to go through the proxy.

--James.
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to