hellron Posted March 10, 2005 Report Share Posted March 10, 2005 first a simple question, how can i set windows so when i turn on computers on a domain the default log on is to the domain rather than the local computer, without diabling the user account on the local machine? i assume it must be easy and to be honest assumed it would be the default setting.more complicated and probably un answerable question is:ive got a couple of proliant 3000's running server 2003 on a domain, all i want to do is share the internet but only to those people who are logged in on the domain making a wifi connection secure, i tried using kerio winroute firewall which was good but due to the lack of a socks service could allow some p2p protocols through it, but the authetication with the active directory was great, so i thought id try ISA which is worse i tried creating rules for users but this was poor and i cant make this work with p2p either, has anyone any suggestions?thanks you for your patience Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 10, 2005 Report Share Posted March 10, 2005 Hello hellron,The first task is simple. I'm not so sure the second one is. I think for the XP Domain Login, if you select it once, log in, then click Options at next login, you'll be all set. I've only seen it default to local login immediately after the PC's added to the Domain. After you've logged into the Domain once, I think it defaults to the Domain. There's probably an Active Directory Policy that could be made to "make" all the XP machines default to the Domain, but that seems like a little more work than is necessary.The second one I'll look into. Most of the solutions I'm aware of involve a third party hardware device like Blue Socket, or a Nortel or Cisco solution. Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 14, 2005 Report Share Posted March 14, 2005 Hellron,I've been searching around a little for controlling Internet access using Active Directory, and haven't found anything that doesn't require some outside device or software yet. Active Directory login's control access to Active Directory resources like folders, printers, mailboxes, etc. The Internet connection isn't generally an Active Directory resource, unless you're using an ISA Server (I have worked on ISA Servers for customers before, but have reservations about having a Microsoft product acting as a firewall). Are you able to spend any time or money on a device to control access? How many users? I may be able to recommend some options. Quote Link to comment Share on other sites More sharing options...
scuzzman Posted March 15, 2005 Report Share Posted March 15, 2005 Maybe this could be as simple as a router with port forwarding/packet filtering enabled - essentially just a NAT. Just restrict all ports except 80 (http) and 53 (dns) with a default DROP policy for incoming and outgoing connections and this will limit the connection to just surfing and nothing else. Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 15, 2005 Report Share Posted March 15, 2005 Scuzzman, That may fill the bill, but as noted here:all i want to do is share the internet but only to those people who are logged in on the domainI think he wants it tied into domain logins somehow. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.