- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortigate Proxy chaining to use Authentification
Dear colleagues, I encountered the issue of authentication of external proxy servers.
I have a Fortigate 100F - new, configured Explicit proxy. To connect to an external proxy server, I try to use the Proxy chaining function, everything would be fine, but the external proxy server requires user authentication when connecting to itself, I could not find this function in the settings. I also reviewed all the cookbooks and also did not find anything.
On one of the resources I found only these lines: config web-proxy global
forward_proxy_auth Enable , but when I try to use it it shows Error about upsent function.
- Labels:
-
Authentication
-
Explicit proxy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Alex,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Alex,
We are still looking for someone to help you.
We will come back to you ASAP.
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Alex,
To configure FortiGate proxy chaining with authentication:
- Set up the first FortiGate unit with authentication, such as Kerberos.
- Configure the second FortiGate unit with a different authentication method, like NTLM.
- Ensure that the first FortiGate forwards traffic to the second FortiGate.
- Note that the second FortiGate will respond with HTTP 407 (Proxy Authentication Required) to the client.
- Understand that the client may get confused as it is already authenticated with the first FortiGate.
- The first FortiGate unit will not forward the Proxy-Authorization header to the second FortiGate unit to prevent credential leaks.
- It is not possible to achieve dual mixed authentication in this setup.
- The supported setup involves authentication on the first FortiGate unit while the second FortiGate unit performs authorization using the x-auth-user header.
Hope it will help.
Regards,
