• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Force proxy help

Scheduled Pinned Locked Moved Cache/Proxy
5 Posts 3 Posters 1.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    pitt1717
    last edited by May 29, 2017, 9:38 PM

    Not sure how to title this but I have a proxy question I haven't seen asked.

    I have a strict proxy set up and force the lan to use it by firewalling 80 and 443 per the guides. it works but then causes issues with Facebook, twitter App Store etc. Is there any way to force clients to use the proxy other than the firewall block rule? keeping up to date with adding ip addresses to the fw allow list is tiring.
    I tried allowing to go direct to these sites using the pac file, but the force proxy fw rule obviously kicks in

    1 Reply Last reply Reply Quote 0
    • M
      marcelloc
      last edited by May 30, 2017, 3:02 AM

      You can Use a WPAD automatic proxy configuration.

      Treinamentos de Elite: http://sys-squad.com

      Help a community developer! ;D

      1 Reply Last reply Reply Quote 0
      • P
        pitt1717
        last edited by May 30, 2017, 1:29 PM

        I am using WPAD using dhcp opt 252. but if the client doesn't select autoconfig or changes the proxy settings to off it will bypass the proxy and thus defeat the setup right?

        1 Reply Last reply Reply Quote 0
        • M
          marcelloc
          last edited by May 30, 2017, 8:07 PM

          @pitt1717:

          I am using WPAD using dhcp opt 252. but if the client doesn't select autoconfig or changes the proxy settings to off it will bypass the proxy and thus defeat the setup right?

          yes. You can intercept these clients with transparent proxy.

          Treinamentos de Elite: http://sys-squad.com

          Help a community developer! ;D

          1 Reply Last reply Reply Quote 0
          • M
            MBwork
            last edited by Jun 3, 2017, 6:24 AM

            If transparent proxy doesn't work well for you (I've personally found it buggy and decided against it); I've found success in setting up Group Policy to force the WPAD file on users. Defining the AutoConfigURL registry value works well. But if you're totally blocking 80 and 443 all together, I believe you can just set the ProxyServer registry value and not even need the WPAD file. (that is, depending on your environment. I'm assuming an all Windows Active Directory setup.)

            https://blogs.msdn.microsoft.com/askie/2015/07/17/how-can-i-configure-proxy-autoconfigurl-setting-using-group-policy-preference-gpp/

            https://support.microsoft.com/en-us/help/819961/how-to-configure-client-proxy-server-settings-by-using-a-registry-file

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received