Last Saturday I finally installed and activated Wingate. But, as a result, I did not replace our old gateway, because I wasn't able to solve one small problem. And now we are still using the old system.
I made all settings as wanted: Guest was removed from the "Users" group, default rights where removed, after my users were granted necessary rights. I also made necessary assumptions, as I am using "No authentication with Assumed users" mode.
I setup only DNS and ENS system services for all of my users (plus RCS for Admins and security officers), other system services disabled; and WWW and FTP Proxies (plus LogFile server for Admins and security officers), other user services deleted.
After setting Wingate address and appropriate port as Proxy on a test client browser Internet worked fine! => Proxy service is working, client has necessary rights.
I also need for some sites and addresses (and only them) to be accessed via NAT, not proxy. What I did for it:
1. NAT was enabled, necessary rights granted, with white list (Advanced tab, separate filters with one criterion in each: like, say, "Server name" contains "www.test.com" and "Server ip" equals 100.100.100.100).
2. Traffic interception (Transparent proxy) disabled in the used user services, including web proxy.
3. On the client's browser "www.test.com" added to the list of exceptions - sites, which has to be accessed by not using proxy.
The result: site is not accessible!
I checked "nslookup http://www.test.com" - it resolves name ok (but wrote DNS server is unknown - is this ok?). So the problem is not DNS, it is NAT. But what could be the reason?
I checked bindings, recipients and granted rights, everything seems to be ok.
P.S. Just in case it is important: I also made some OS security tunings:
- disable NBT on all interfaces
- disable OS services bindings on all interfaces, except “F&P sharing for MS Networks” on LAN
- in security policy changed some settings, but I think only one could be important for the issue: "Access this computer from the network". I grant this privilege to Admins and SO users only.
Need your help.
P.P.S.S. As proxy is working and DNS is working too, the problem must be in NAT, and most probably in NAT access rights. But everything is ok there: required group has “Can access this service” right with “User may be assumed” option plus in the System policy the same group has “Users can access services” right also with “User may be assumed” option (Default rights = MUST also be granted). Plus for NAT the above mentioned filters are applied.
I did not try without any filters for NAT, was too tired. Right now I can not try it, users are working. I want to analise and understand all possible reasons, then I'll try again in dinner hours.
I want to mention again: web proxy is working for the test user, DNS resolves site name for the user, but the site is not opening...