Skip to main content
hapklaar
New Member
November 14, 2016
Question

FortiGate and kerberos authentication to explicit proxy

  • November 14, 2016
  • 3 replies
  • 10692 views

I' trying to configure kerberos so clients can use this to authenticate to the explicit web proxy. The release notes talk about this very briefly, but cannot find any info on what steps need to be taken to configure this. The first is pretty self-explanatory and can also be configured from GUI. But the second, where we need to configure the account in the AD which is mapped to the SPN is not.

 

- Where do I for example get the base64 encoded keytab? 

- Is the LDAP server the profile name that can be configured in the GUI, or do I need to specify a host name?

 

I guess as this feature is quite new Fortinet hasn't gotten around to describe it in more detail yet. Can someone provide the steps to do this?

Support Kerberos and NTLM authentication (370489)

FortiGate now recognizes the client's authentication method from the token and selects the correct authentication scheme to authenticate successfully.

CLI syntax
config firewall explicit-proxy-policy

edit <example>

set active-auth-method [ntlm | basic | digest | negotiate | none]

end

 

Explicit web proxy Kerberos authentication support (297503)

The following web proxy Kerberos authentication CLI syntax has been added:

CLI syntax
config user krb-keytab

edit <example>

set principal // Kerberos service principal

set ldap-server // LDAP server name

set keytab // base64 coded keytab

 

 

    3 replies

    anda37
    New Member
    November 25, 2017

    Hello,

     

    i want to use the same Configuration. 

     

    is there any Update for this topic?

     

    thanks

    blackhole_route
    New Member
    December 2, 2017

    I think I have some notes on this setup process that we received from our Fortinet account team during our eval/poc phase. I'll check in the office and post back.

    mac987
    New Member
    November 16, 2020

    Hi Good morning

     

    I appreciate this is an old post but did you ever find out where to get the keytab base64 file from, do we generate it on the ldap server then import it into the FG ? I have tried to generate a random string as part of the generation but it wants a file name.

    many thanks

    mac

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!