- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
KDC Proxy
It looks like only with KDC Proxy setup my SMB Shares can be accessed by ZTNA Users.
Problem is that the KDC Proxy Setup is not very well described nor I find a detailled description on the web that helps me figure out enough details.
There is this Fortinet article
And I also found this for KDC setup.
https://syfuhs.net/kdc-proxy-for-remote-access
My biggest question is, what is the correct URL that needs to be entered in the client Group policy so KDC Proxy is reached.
Another question is if and how I can
- Labels:
-
FortiClient EMS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Christoph,
the guide you shared actually specifiec the registry settings to be applied:
Configuring registry keys on clients
If you are trying to deploy these settings on a client machine that cannot retrieve group policy updates, manually configure the registry keys for the client:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos] "KdcProxyServer_Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\KdcProxy\ProxyServers]
"*"="<https kdcproxy.fortitest.net />" or ".fortitest.net"="<https kdcproxy.fortitest.net />"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters] "NoRevocationCheck"=dword:00000000
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In the client registry there is no Kerberos Section at all
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I managed to use Kerbereos now!
Problem is that my network drives are defined in group policys.
So when connecting via ZTNA the drives are not reconnected.
Is there another port or Service that can be used via ZTNA to apply group policys?
Only option at the moment is to enter
net use * /delete /y
Then I can connect a drive again manually.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Christian,
Is SMB driving working for you now without prompting for username and password through ZTNA.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Only when I connect new shares, existing ones that were connected within domain are not reconnected at all
