Description
This article describes how to configure explicit proxy and authenticate users using NTLM protocol.
Solution
1) Enable web proxy.
data:image/s3,"s3://crabby-images/ce057/ce057c7375b0827770e01dcd87686137a9c11d8f" alt=""
2) Add a LDAP server.
data:image/s3,"s3://crabby-images/4a79c/4a79ccb364b9dcc0f5f2dae47621fd882dfca635" alt=""
3) Configure authentication scheme.
Create new domain controller by selecting '+ Create tab'.
data:image/s3,"s3://crabby-images/7ad29/7ad294ae2f039a442bb57c4c94a933599dbaca35" alt=""
Select the method to be NTLM and from the domain controller drop down list select the domain controller created in the prior step:
data:image/s3,"s3://crabby-images/427c9/427c9dfa4ecab317e1ac07797c1b5897a81cf400" alt=""
Alternative is CLI commands given below, showing how to configure domain controller and authentication scheme on FortiGate:
# config user domain-controller4) Configure authentication Rule.
# config user domain-controller
edit "DC"
set ip-address <LDAP-Server-IP>
set port 445
set domain-name "labdc.local"
set ldap-server "LDAPSRV"
next
end
# config authentication scheme
edit "NTLMNEW"
set method ntlm
set domain-controller "DC"
set fsso-guest disable
next
end
Select protocol to HTTP.
Then select the NTLM method previously configured and disable IP-based authentication.
Then select the NTLM method previously configured and disable IP-based authentication.
data:image/s3,"s3://crabby-images/1231a/1231a030a1f8505df84121b16bf651776787774a" alt=""
# config authentication rule5) Configure 'User Group':
edit "NTLMNEWRULE"
set status enable
set protocol http
set srcaddr "VMware address"
set ip-based disable
set active-auth-method "NTLMNEW"
set web-auth-cookie disable
set comments ''
next
end
Select type to Firewall, select 'Add' under Remote Groups, select the remote LDAP server and assign the user group that already exists on the domain controller.
data:image/s3,"s3://crabby-images/2ff54/2ff54b867302ca7b530995c1fe179931656988eb" alt=""
6) Last step configure Proxy policy as show in the below figure:
data:image/s3,"s3://crabby-images/e50a0/e50a00a49b8012d3ed2019b053d5653738ce9707" alt=""
7) Testing Phase:
A pop-up window appears when user tries to access a web page.
A pop-up window appears when user tries to access a web page.
data:image/s3,"s3://crabby-images/8f41c/8f41c391af208e466cc48d129958bf56dfd70603" alt=""
data:image/s3,"s3://crabby-images/5f2ba/5f2ba8f263abaaa49a03724e66d8f8ec26146354" alt=""
8) Using Curl method.
data:image/s3,"s3://crabby-images/a4eba/a4ebae8bce3fccbae55b699a33e6057962f1f81d" alt=""
curl --proxy-ntlm --proxy-user Username:Password --proxy <PROXY_URL:PORT>
Note.
If user does not authenticate no logs will appear in the FortiGate 'User Events'.
If user does not authenticate no logs will appear in the FortiGate 'User Events'.
However, if the browser is closed after successfully authenticating NTLM credentials and kept the session idle for more than 5 minutes (Default proxy session timeout 5 min), then an authentication timed-out under User Events will appear.
data:image/s3,"s3://crabby-images/a4eba/a4ebae8bce3fccbae55b699a33e6057962f1f81d" alt=""
# diagnose wad user list
FGT # diagnose wad user list
ID: 1, VDOM: root, IPv4: 192.168.108.22
user name : aduser2
worker : 3
duration : 153
auth_type : Session
auth_method : NTLM
pol_id : 1
g_id : 5
user_based : 0
expire : 248
LAN:
bytes_in=119053 bytes_out=1258224
WAN:
bytes_in=937468 bytes_out=80500
prior FortiGate version visible auth_method = 2
auth_method = 2 <----- Means the user has been authenticated using NTLM method.
Related Articles
Labels: