Hi,
1. I am assuming that the 2003 server is Domain Controller for the Domain?
If it is then you can create new OU's in Active Directory Users and Computers.
Once you have created the OU right click and select properties. You should see a Group Policy tab which you can use to create your policy
2. Sorry, didnt explain that very well. If you have some local web servers for an intranet say then you will have to add the addresses of the web servers to the exception box on the proxy page otherwise all of the computers in the restricted OU will not be able to access them.