> If you set the authentication scheme to use only ntlm and set the rule > to allow only traffic that matches that acl. Yes, but I don't want the user not to be allowed to surf the Internet from a computer that isn't connected to the Active Directory domain. For example, I don't want the user to use their laptops even if they insert their user and password in the proxy authentication. Thank you!