WPAD And Zone detection

I

ITmab

Guest
We are having a very strange issue.
We have a simple wpad script enabled which directs two domains to a proxy server, other domains are set to go to the web directly without the proxy.

If we configured IE to use the "Automatically detect settings" setting or define it as a PAC we are indeed seeing that the domains are directed via the proxy and all others are not, thus far everything works as expected.

Now the strange behaviour; if the "Automatically detect settings" or the PAC are used all sites are seen as part of the Local Intranet Zone.
This is a major security risk and unacceptable in our Org.
Disabling either setting restores the proper zone handling and the undefined sites are part of the Internet Zone.

In the Local Intranet Zone option both the GPO options "Intranet Sites: Include all local (intranet) sites not listed in other zones" and "Intranet
Sites: Include all sites that bypass the proxy server" are set to disabled.
Has anyone seen this before?

Continue reading...
 
Back
Top