Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AlexBay
New Contributor

Fortigate Proxy chaining to use Authentification

Dear colleagues, I encountered the issue of authentication of external proxy servers.
I have a Fortigate 100F - new, configured Explicit proxy. To connect to an external proxy server, I try to use the Proxy chaining function, everything would be fine, but the external proxy server requires user authentication when connecting to itself, I could not find this function in the settings. I also reviewed all the cookbooks and also did not find anything.
On one of the resources I found only these lines: config web-proxy global
forward_proxy_auth Enable , but when I try to use it it shows Error about upsent function.

3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello Alex,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello Alex,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hi Alex,

 

To configure FortiGate proxy chaining with authentication:

  1. Set up the first FortiGate unit with authentication, such as Kerberos.
  2. Configure the second FortiGate unit with a different authentication method, like NTLM.
  3. Ensure that the first FortiGate forwards traffic to the second FortiGate.
  4. Note that the second FortiGate will respond with HTTP 407 (Proxy Authentication Required) to the client.
  5. Understand that the client may get confused as it is already authenticated with the first FortiGate.
  6. The first FortiGate unit will not forward the Proxy-Authorization header to the second FortiGate unit to prevent credential leaks.
  7. It is not possible to achieve dual mixed authentication in this setup.
  8. The supported setup involves authentication on the first FortiGate unit while the second FortiGate unit performs authorization using the x-auth-user header.

 

Hope it will help.

 

Regards,

Anthony-Fortinet Community Team.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors