Skip to main content
ciscomemo
New Member
May 25, 2015
Question

ntlm and authentication page

  • May 25, 2015
  • 9 replies
  • 20672 views

I am working on FortiOS 5.2.3 ( latest one) and have configured SSO on it . Now I wanted computers which are not a part of domain to be prompted for a user/pass login page when they try to access the internet. For this I configured "set ntlm enable" and "set ntlm-guest enable" command under the firewall policy .

 

When I try to access the internet a popup will show up asking for user/pass , once I put the domain user pass it will get auehtnciated and internet will work. In fortigate user section that user will also show up as NTLM based authentication.

 

THe only problem here is that I want to avoid the popup and want that fortigate login page instead. I thought this might be some browser problem so i tried IE , chrome and firefox and on all same thing comes up and not a login page.

 

Please guide how to get the login page instead of the popup

    9 replies

    xsilver_FTNT
    Staff
    Staff
    May 25, 2015

    I'm afraid that NTLM will always cause web browser to trigger login pop-up window and not a web form.

     

    If you want to have customized form based authentication page (ala standard web page with login form), then the only way is explicit proxy and its policy, with IP based you would be able to choose primary auth method (pasive) as FSSO, and secondary (active authentication which does require user interaction) as Form based, and then you can customize replacement messages to tune-up login form.

    Note that explicit proxy does slow down the overall throughput, as it's proxy. So form based logon possibility has its price.

    ciscomemo
    ciscomemoAuthor
    New Member
    May 26, 2015

    xsilver wrote:

    I'm afraid that NTLM will always cause web browser to trigger login pop-up window and not a web form.

     

    If you want to have customized form based authentication page (ala standard web page with login form), then the only way is explicit proxy and its policy, with IP based you would be able to choose primary auth method (pasive) as FSSO, and secondary (active authentication which does require user interaction) as Form based, and then you can customize replacement messages to tune-up login form.

    Note that explicit proxy does slow down the overall throughput, as it's proxy. So form based logon possibility has its price.

    can you please share config for this

    xsilver_FTNT
    Staff
    Staff
    May 26, 2015

    If you are asking for config of explicit proxy then there is nothing special, just standard config gives you those opportunities, check FortiGate GUI for explicit proxy firewall policy or docs.fortinet.com site for guides.

    rezendecs
    New Member
    August 19, 2015

    I hope that this answer still can help you!!!!

     

         Look the link bellow.

         https://www.linkedin.com/grp/post/1769457-5919733185838600193

     

     

    Regards,

    Claudio 

    Wurstsalat
    Explorer
    October 18, 2016

    NTLM is never a loginpage...it is send from the client so it will always this popup.

     

    But dont ask me how to get the Login page...i will use/test this only in the near future (never used it before) ;)

    rwpatterson
    New Member
    October 18, 2016

    When I dealt with NTLM way in the past, it only passed through with IE. Other browsers presented a web dialogue due to the lack of Active X, I believe...

    Wurstsalat
    Explorer
    October 19, 2016

    Chrome should understand NTLM by default

    Firefox has to be configured for NTLM (have a look at about:config + search for ntlm)

     

    This is not cause of the lack of any active x stuff

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!