Skip to main content
kcapecchi
Staff
Staff
September 18, 2015

Technical Note: Use of web-auth-cookie feature to reduce authentication requests

  • September 18, 2015
  • 0 replies
  • 2612 views
Description
With FSSO / NTLM and since v4.0 MR3 and v5.0, more authentication requests are generated from the FortiGate unit.

In a large structure where a lot of authentication requests can be generated, it is a good practice to enable the parameter 'web-auth-cookie' on the proper policy:
web-auth-cookie {enable | disable}
This helps to reduce the number of authentication requests to the authentication server when session-based authentication is applied using explicit web proxy. This is only available when session based authentication is enabled.

When this parameter is enabled only one request by session is authenticated.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!