Dear all,
I just read this KB
, and it looks good to my operation.
So I tried to set up one Evaluation Fortigate and see if Form-based Auth is also supported.
But seems no luck here.
The Form-based auth only appeared when I selected HTTP protocol.
If I selected Socks. No luck then.
Is there any way to achieve Captive portal + Local User DB + Socks-based proxy Auth on Fortigate?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello Potato,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Dear Potato,
The idea of achieving form based authentication using socks sounds better but I guess its not possible. We must understand how the underlying protocol works.
Socks is functioning at layer4 while form based authentication at layer7. Again, when implementing socks authentication defined in rfc 1928 (https://datatracker.ietf.org/doc/html/rfc1928) , the acceptable methods defined in protocol are below,
-----------------------------------------------------------------------------------
The values currently defined for METHOD are: o X'00' NO AUTHENTICATION REQUIRED o X'01' GSSAPI o X'02' USERNAME/PASSWORD o X'03' to X'7F' IANA ASSIGNED o X'80' to X'FE' RESERVED FOR PRIVATE METHODS o X'FF' NO ACCEPTABLE METHODS
Compliant implementations MUST support GSSAPI and SHOULD support USERNAME/PASSWORD authentication methods.
------------------------------------------------------------------------------------------------
So if socks proxy has to authenticate the socks client, the username/password would have been supplied already by the client over the socks connection it attempted (so no need for or thoughts for different auth methods if socks is solely used by the client). Also, if no authentication required was chosen by the socks client, and on FortiGate we enabled socks authentication, the connection terminates failing authentication.
Best regards,
Jin
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1640 | |
1066 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.