<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Users always want to fight The Man</title>
	<link>http://ask.metafilter.com/84948/Users-always-want-to-fight-The-Man/</link>
	<description>Comments on Ask MetaFilter post Users always want to fight The Man</description>
	<pubDate>Fri, 29 Feb 2008 10:06:06 -0800</pubDate>
	<lastBuildDate>Fri, 29 Feb 2008 10:06:06 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: Users always want to fight The Man</title>
		<link>http://ask.metafilter.com/84948/Users-always-want-to-fight-The-Man</link>	
		<description>How do you prevent terminal services users from disabling the Firewall Client for ISA in Server 2003? &lt;br /&gt;&lt;br /&gt; This is probably an easy one, but I don&apos;t have a lot of time to google around for the answer today. How do I prevent Server 2003 terminal services users from disabling the ISA firewall client? Currently the best solution I can find is to disable the taskbar icon, but for troubleshooting purposes I&apos;d rather just leave that alone. This seems pretty ridiculous, there&apos;s got to be a way, right?</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2008:site.84948</guid>
		<pubDate>Fri, 29 Feb 2008 08:30:03 -0800</pubDate>
		<dc:creator>tracert</dc:creator>
		
			<category>ISA</category>
		
			<category>FirewallClient</category>
		
			<category>Server2003</category>
		
			<category>TerminalServices</category>
		
	</item> <item>
		<title>By: Climber</title>
		<link>http://ask.metafilter.com/84948/Users-always-want-to-fight-The-Man#1256115</link>	
		<description>A workaround would be to see if you can hide the icon.  &lt;br&gt;
&lt;br&gt;
In the common.ini add&lt;br&gt;
&lt;br&gt;
[TrayIcon]&lt;br&gt;
TrayIconVisualState=0&lt;br&gt;
&lt;br&gt;
It should work for 2004 and 2006.&lt;br&gt;
Granted, I haven&apos;t used it in a long time.  I have just gone the way of securenat clients.  Easier to deal with, but not as much control.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.84948-1256115</guid>
		<pubDate>Fri, 29 Feb 2008 10:06:06 -0800</pubDate>
		<dc:creator>Climber</dc:creator>
	</item><item>
		<title>By: purephase</title>
		<link>http://ask.metafilter.com/84948/Users-always-want-to-fight-The-Man#1256388</link>	
		<description>You can use group policy to restrict their access to the services MMC and the task manager, I believe there is an option in the client install to not display in the system tray as well.&lt;br&gt;
&lt;br&gt;
Granted, you could still kill the service through the command line, so use group policy to disable that. Also, if you&apos;re simply preventing browsing to certain sites then they can easily workaround the proxy by removing it in IE so use group policy to restrict the ability to manage IE settings.&lt;br&gt;
&lt;br&gt;
So, easy answer. Learn about group policy.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.84948-1256388</guid>
		<pubDate>Fri, 29 Feb 2008 14:22:27 -0800</pubDate>
		<dc:creator>purephase</dc:creator>
	</item><item>
		<title>By: tracert</title>
		<link>http://ask.metafilter.com/84948/Users-always-want-to-fight-The-Man#1256547</link>	
		<description>They are locked down pretty hard, actually, with all that and then about 200 or so more things. I wrote the GPO myself. Browsing is fine, but I want ISA server to log applications traffic too. Without the firewall client, it just logs a bunch of anonymous SecureNAT connections coming from the terminal servers, when we would actually like to know which user is doing what with which app (and when! Metrics are fun). &lt;br&gt;
&lt;br&gt;
The problem is that the icon is visible in the system tray for all users that run the FWC, and you can click on it and disable it regardless of privileges. It&apos;s not horrible if they disable it because they obviously can&apos;t change gateway settings or routes, but people will probably click it thinking that&apos;s what it will do anyway. I would like the icon to be visible, but for the users not to be able to change settings. This seems to be not very easily done, though, unless I&apos;m missing a setting somewhere (which I think I probably am).</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.84948-1256547</guid>
		<pubDate>Fri, 29 Feb 2008 17:01:18 -0800</pubDate>
		<dc:creator>tracert</dc:creator>
	</item><item>
		<title>By: tracert</title>
		<link>http://ask.metafilter.com/84948/Users-always-want-to-fight-The-Man#1258857</link>	
		<description>&lt;strong&gt;Quick and dirty solution&lt;/strong&gt;: I used software restriction policy to prevent non admin users from running the management tool (FwcMgmt.exe). Admin users can still run it to troubleshoot, and everyone else doesn&apos;t know it&apos;s there.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.84948-1258857</guid>
		<pubDate>Mon, 03 Mar 2008 08:59:30 -0800</pubDate>
		<dc:creator>tracert</dc:creator>
	</item>
	</channel>
</rss>
