Skip to main content
AlexBay
New Member
February 11, 2025
Question

Fortigate Proxy chaining to use Authentification

  • February 11, 2025
  • 3 replies
  • 845 views

Dear colleagues, I encountered the issue of authentication of external proxy servers.
I have a Fortigate 100F - new, configured Explicit proxy. To connect to an external proxy server, I try to use the Proxy chaining function, everything would be fine, but the external proxy server requires user authentication when connecting to itself, I could not find this function in the settings. I also reviewed all the cookbooks and also did not find anything.
On one of the resources I found only these lines: config web-proxy global
forward_proxy_auth Enable , but when I try to use it it shows Error about upsent function.

3 replies

Anthony_E
Staff
Staff
February 14, 2025

Hello Alex,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks

Best Regards
Anthony_E
Staff
Staff
February 19, 2025

Hello Alex,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Best Regards
Anthony_E
Staff
Staff
February 20, 2025

Hi Alex,

 

To configure FortiGate proxy chaining with authentication:

  1. Set up the first FortiGate unit with authentication, such as Kerberos.
  2. Configure the second FortiGate unit with a different authentication method, like NTLM.
  3. Ensure that the first FortiGate forwards traffic to the second FortiGate.
  4. Note that the second FortiGate will respond with HTTP 407 (Proxy Authentication Required) to the client.
  5. Understand that the client may get confused as it is already authenticated with the first FortiGate.
  6. The first FortiGate unit will not forward the Proxy-Authorization header to the second FortiGate unit to prevent credential leaks.
  7. It is not possible to achieve dual mixed authentication in this setup.
  8. The supported setup involves authentication on the first FortiGate unit while the second FortiGate unit performs authorization using the x-auth-user header.

 

Hope it will help.

 

Regards,

Best Regards
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!