Dear supporters,
I have Wingate 6.22 installed on W3K R2 SP1. One internal and one external adapter.
Wingate is used for Proxy need only (specified in browser settings).
1. I have created 4 Active Directory groups: Internet Restricted, Internet Limited, Internet Extended, Internet Full.
- Restricted group has access only to some websites.
- Limited has access to most resources except banned one.
- Extended has almost no limit
- Full has full access
I want Domain Users to be members of Restricted and Limited groups. As Restricted has criterion based on IP address, so all Domain users except certain IPs will have Limited access, not restricted.
But practice shows that Wingate does not understand that certain user, which is member of Domain Users and which is member of Internet Limited group, should have rights to access internet. It seems that Wingate does not look recursively deeply into the group, only one level deep. Is it possible to fix somehow?!
2. We have set NTLM authentication and "User must be authenticated" in policy. Everything seems to work just fine.
The only thing is that:
- Users time to time change passwords
- Not always users switch off PCs or even log off for the night
- Some users have notebooks and do work offline, so log-on credentials are cached
I think this causes problems with authentication window popping up and asking for user name and password, whats is very inconvenient and annoying. Sometimes even restart does not help and you are forced to enter credentials each time you open Internet Explorer. Is is curable somehow?