It looks like only with KDC Proxy setup my SMB Shares can be accessed by ZTNA Users.
Problem is that the KDC Proxy Setup is not very well described nor I find a detailled description on the web that helps me figure out enough details.
There is this Fortinet article
And I also found this for KDC setup.
https://syfuhs.net/kdc-proxy-for-remote-access
My biggest question is, what is the correct URL that needs to be entered in the client Group policy so KDC Proxy is reached.
Another question is if and how I can
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Christoph,
the guide you shared actually specifiec the registry settings to be applied:
If you are trying to deploy these settings on a client machine that cannot retrieve group policy updates, manually configure the registry keys for the client:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos] "KdcProxyServer_Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\KdcProxy\ProxyServers]
"*"="<https kdcproxy.fortitest.net />" or ".fortitest.net"="<https kdcproxy.fortitest.net />"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters] "NoRevocationCheck"=dword:00000000
Regards
In the client registry there is no Kerberos Section at all
I managed to use Kerbereos now!
Problem is that my network drives are defined in group policys.
So when connecting via ZTNA the drives are not reconnected.
Is there another port or Service that can be used via ZTNA to apply group policys?
Only option at the moment is to enter
net use * /delete /y
Then I can connect a drive again manually.
Hi Christian,
Is SMB driving working for you now without prompting for username and password through ZTNA.
Only when I connect new shares, existing ones that were connected within domain are not reconnected at all
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1645 | |
1070 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.