You really need to set this with a GPO and not a login script, otherwise the users can simply change the proxy settings at will. Also, without a proxy, exactly how do you plan to control access?? Do you have an existing proxy? If so, is it single leg or pass-thru? Single leg proxies are easy to bypass unless you incorporate specific rules to block web access in your routers.
ISA is one of the few firewalls that integrates with AD, so you can define access by group. I'm not sure about squid's current capabilities - been years since I played with it. IPCop is another firewall/proxy, but again, I don't know about user auth capabilities.
ISA shouldn't be a hard sell, since it can be your Internet firewall, proxy, and application publishing system all in one. Considerable cost savings over a "hardware" firewall and much more secure, since traffic never "passes through" an ISA firewall (unlike traditional firewalls that "open ports" to allow traffic "through" the firewall.
I use two ISA firewalls in my office to provide a screened subnet where our WiFi gateway lives along with our mail relay and public web farm. The back firewall is an Enterprise version that publishes two internal apps and our VPN. It also controls access between the workstation LAN and the server LAN segments.
Glenn
_________________________
Actually I
am a Rocket Scientist!