So instead of the way the line is now: acl InetAllow external AD_global_group CLW.Squid.Full The domain would be added to the group like below: acl InetAllow external AD_global_group NA\CLW.Squid.Full On Wed, Apr 21, 2010 at 06:19, Guido Serassio <guido.serassio@xxxxxxxxxxxxxxxxx> wrote: > Hi, > >> >> We have the below acl for users in the Ad global group >> >> >> >> >> >> external_acl_type AD_global_group ttl=120 %LOGIN >> >> c:/squid/libexec/mswin_check_ad_group.exe -G >> >> >> >> and another acl below that allows full access thru the squid proxy >> >> using an ad group >> >> >> >> acl InetAllow external AD_global_group CLW.Squid.Full >> >> >> >> >> >> any ideas???? >> > > > AGAIN: > > "When using mswin_check_ad_group.exe 1.x in global mode (-G options), > the check is done always against a global group placed in the user's > domain." > > So the question is: On which AD domain is defined the CLW.Squid.Full > group ? > > Regards > > Guido > > Guido Serassio > Acme Consulting S.r.l. > Microsoft Gold Certified Partner > VMware Professional Partner > Via Lucia Savarino, 1 10098 - Rivoli (TO) - ITALY > Tel. : +39.011.9530135 Fax. : +39.011.9781115 > Email: guido.serassio@xxxxxxxxxxxxxxxxx > WWW: http://www.acmeconsulting.it > > > >