Skip to main content
KhizerSaleem
New Member
May 31, 2018
Question

Kerberos Authentication Configuration

  • May 31, 2018
  • 14 replies
  • 23918 views

Hi All,   I need the authentication while using explicit-web-proxy.   The matter of fact is that obviously, it needs Kerberos authentication for authentication of AD-Users but in the documents on the given link below, by Fortinet, it didn't give us the picture clearly. I read the authentication document in which it defines all Kerberos authentication process.    http://help.fortinet.com/...it%20proxy%20users.htm  

 Can I configure the FortiOS 5.6.x authentication settings on FortiOS 6.0, as I'm using this on Fortigate-VM 64 on evaluation period, or I need to set up the only Kerberos environment?

 

I want to know that is there any good guide or any video that can show us how to configure the process or do you have any kind of notes regarding this.    Hope to see your kind reply soon.   Thnks in advance.   Best Regards Khizer Saleem

    14 replies

    xsilver_FTNT
    Staff
    Staff
    May 31, 2018

    Hi,

    mentioned help doc is quite complex and should cover most of the usual configuration variants.

    Basically said you have to decide between explicit/transparent proxy and ip-based/session-based authentication.

    And then follow the steps for one of those four basic config variants.

    Config is supposed to be same or very similar (not aware of any deviation) between 5.6 and 6.0 FortiOS.

    You need those parts .

    - LDAP server and group

    - KRB keytab

    - policy

    - config authentication parts defining schedules/rules etc.

     

    Kind regards, Tomas

    KhizerSaleem
    New Member
    June 1, 2018

    Hi,

     

    Well, thanks Tomas for your kind reply, yes the document is too complex neither Fortinet made any video on their video library, so its too complex I tried all the things but don't know which thing is missing.

     

    Thanks for your reply.

     

    Best Regards

    Khizer Saleem

     

    FortiBoris_FTNT
    Staff
    Staff
    February 23, 2019

    Hey all, Doing some Kereros + Explicit Proxy testings on v6.0.4. Simple question, how is a user mapped towards multiple AD groups?? For the moment it seems i'm mapped to the 1st group alphabetically and not multiple groups. The idea would be multiple AD groups mapped to different Explicit Proxy rules each having different Web Filtering profiles applied. Although, we would want to have the possibility to map users within multiple groups, hence mapped to different Web Filtering profile (Social_Surfers, Sports_Surfers, Hacking_Surfers etc...). You add Bob within Social_Surfers group @AD and it dynamically can surf Social Networks on the fly while keeping it's previous surfing "rights" from say Sports_Surfers where he also belongs.

     

    That scheme is possible with FSSO but couldn't reach my goal with Kerberos. User seems mapped to only ONE group while being members of more than one.

     

    Thanks,

    Boris

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!