On Jul 24, 2011 2:34 PM, "Andrew Miehs" <[email protected]> wrote: > > And this works? If the users can change their proxy settings, they can normally change > c:\windows\system32\etc\hosts (or whatever the file is called). > > The only solution we have found that really works is not allowing clients directly into the > Internet. All traffic must traverse the DMZ. If they want http, they need to use the HTTP > proxy that we provide them - not that they have much choice - group policies, etc.
Yes, the default gateway for the clients where Linux boxes running iptables with squid and squidGuard, acting as transparent proxies, you had no choice but to go through the proxy. --James. _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
