Hi All,
I have a scenario where I need to use the Explicit proxy and NTLM authentication. We are replacing another web proxy solution that is currently doing this. The authentication needs to be transparent and current is, so the browsers are configured to provide authentication responses already.
We are currently using FortiOS 5.4.
I have read some posts which seem to suggest that we require Fortigate/LDAP and FSSO - -but i am confused as to why we would need an FSSO collector in this setup.
Would the explicit proxy not just challenge the user browser and then based on the username returned perform an LDAP query to get the user/group membership details and then check the proxy policies?
Is an FSSO collector required in this setup and if so why?
Thanks, Moby.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi James,
I will try that tomorrow. I also think it may be some settings on the DC that need to be changed. I tried some debug like diag debug app authd -1 and diag debug app fnbamd -1 but it didn't show anything useful.
Does anyone know if we can test the NTLM between the fortigate and the DC with a test command?
Like you can with diag test authserver ldap
Thanks, Moby.
Hi All,
Many thanks for all of your feedback - -It is now working. I have a couple more questions that someone may be able to help with:
What is the authentication timeout time and method - -can it be changed?
I want to add a second domain controller to the config - -do you just add a second one- -if so which one will the Fortigate use as primary?
Thanks, Moby.
Hi James,
Thanks for the feedback. I do get what you are saying, but it seems a bit of a complicated way of doing it. With LDAP I can just add a secondary server into the LDAP config as below:
edit LDAP_Server
set server 1.1.1.1
set secondary-server 1.1.1.2
So I am wondering if there is any similar method for "config user domain controller" or if you can add to domain controllers then which would be used and would the second be used if the first does not respond.
Thanks, Moby.
Moby thanks for the details.
Ken
PCNSE
NSE
StrongSwan
Hello Moby,
we also have problems to setup explicit proxy with ntlm and get the error message "access denied the page you requested has been blocked by a firewall policy restriction". Can you describe how you fix the problem in your case ?
Thanks, Kaleun.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.