Currently we are using a FortiGate with explicit proxy in our environment because we have always used a proxy in the past to control which users get access to the internet and which do not. The same FortiGate is also the main firewall and default gateay. On the proxy policies, we use the following security features:
- SSL Deep Inspection
- Antivirus
- Web Filter
- Application Control
- File Filter
The clients get the proxy information via PAC file. However, the proxy address is the same as our default gateway, which means internet connection could be established over normal IPv4 firewall policies as well. From time to time, there is problems with websites or applications that do not go over the proxy correctly. Either there is a problem with authentication (407 Authentication Required) or the websites simply break as soon as any security profile is applied (i.e. the browser returns err_emtpy_response).
That makes me wonder, aside from the user authentication part, are there any benefits of using a proxy in our environment? As far as I can tell, I can also apply SSL Deep Inspection and all the other security profiles (Antivirus etc...) to a normal IPv4 policy, can I not?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi David,
The major benefit of explicit proxy is indeed the user authentication.
Aside of that, you might want to use explicit proxy if you want to completely deny the client PCs direct access to Internet, so they can only have access to the proxy server.
You can have all the UTM features on IPv4 policies.
Regardless, "err_emtpy_response" message should not occur neither on explicit proxy nor IPv4 policy, this has to be investigated and resolved.
There were also some bugs which can cause this error, if you are on an old firmware, you might want to try to upgrade and see if it will be resolved.
Hi David,
The major benefit of explicit proxy is indeed the user authentication.
Aside of that, you might want to use explicit proxy if you want to completely deny the client PCs direct access to Internet, so they can only have access to the proxy server.
You can have all the UTM features on IPv4 policies.
Regardless, "err_emtpy_response" message should not occur neither on explicit proxy nor IPv4 policy, this has to be investigated and resolved.
There were also some bugs which can cause this error, if you are on an old firmware, you might want to try to upgrade and see if it will be resolved.
Thanks for your helpful reply! We are on 6.4.9 but plan to upgrade to 7.X soon. Any recommended version we should upgrade to?
Also I have read somewhere that the proxy offers caching compared to normal IPv4 policies, does that still apply or is it outdated information?
Web caching is possible in both explicit proxy or IPv4 policies.
6.4.11 or 7.0.8, both should be fine.
Hi,
as mentioned by @metz_FTNT earlier, in Proxy authentication you can set methods in "Authentication schemes" like Basic, Certificate based, Digest, Form Based, FSSO, NTLM, SAML Radius Single Sign-on etc..
You can also configure a Keytab file to get Kerberos authentication which is available with "Negotiate" method.
regards,
Sheikh
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.