Technical Note: Use of web-auth-cookie feature to reduce authentication requests
Description
With FSSO / NTLM and since v4.0 MR3 and v5.0, more authentication requests are generated from the FortiGate unit.
In a large structure where a lot of authentication requests can be generated, it is a good practice to enable the parameter 'web-auth-cookie' on the proper policy:
When this parameter is enabled only one request by session is authenticated.
In a large structure where a lot of authentication requests can be generated, it is a good practice to enable the parameter 'web-auth-cookie' on the proper policy:
web-auth-cookie {enable | disable}This helps to reduce the number of authentication requests to the authentication server when session-based authentication is applied using explicit web proxy. This is only available when session based authentication is enabled.
When this parameter is enabled only one request by session is authenticated.
