Jump to content

two simple tasks with a domain


hellron
 Share

Recommended Posts

first a simple question, how can i set windows so when i turn on computers on a domain the default log on is to the domain rather than the local computer, without diabling the user account on the local machine? i assume it must be easy and to be honest assumed it would be the default setting.

more complicated and probably un answerable question is:

ive got a couple of proliant 3000's running server 2003 on a domain, all i want to do is share the internet but only to those people who are logged in on the domain making a wifi connection secure, i tried using kerio winroute firewall which was good but due to the lack of a socks service could allow some p2p protocols through it, but the authetication with the active directory was great, so i thought id try ISA which is worse i tried creating rules for users but this was poor and i cant make this work with p2p either, has anyone any suggestions?

thanks you for your patience

Link to comment
Share on other sites

Hello hellron,

The first task is simple. I'm not so sure the second one is.

I think for the XP Domain Login, if you select it once, log in, then click Options at next login, you'll be all set. I've only seen it default to local login immediately after the PC's added to the Domain. After you've logged into the Domain once, I think it defaults to the Domain. There's probably an Active Directory Policy that could be made to "make" all the XP machines default to the Domain, but that seems like a little more work than is necessary.

The second one I'll look into. Most of the solutions I'm aware of involve a third party hardware device like Blue Socket, or a Nortel or Cisco solution.

Link to comment
Share on other sites

Hellron,

I've been searching around a little for controlling Internet access using Active Directory, and haven't found anything that doesn't require some outside device or software yet. Active Directory login's control access to Active Directory resources like folders, printers, mailboxes, etc. The Internet connection isn't generally an Active Directory resource, unless you're using an ISA Server (I have worked on ISA Servers for customers before, but have reservations about having a Microsoft product acting as a firewall). Are you able to spend any time or money on a device to control access? How many users? I may be able to recommend some options.

Link to comment
Share on other sites

Maybe this could be as simple as a router with port forwarding/packet filtering enabled - essentially just a NAT. Just restrict all ports except 80 (http) and 53 (dns) with a default DROP policy for incoming and outgoing connections and this will limit the connection to just surfing and nothing else.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy