Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pepr
New Contributor

Kerberos authetication without ip-based

I would like to ask somebody, is it possible in fortigate 5.6.x setting explicit proxy with kerberos on AD authentication , when is disabled ip-based authentication? I need have in a log written which user which web site open. Kerberos i need because i do not want use ntlm.

1 REPLY 1
xsilver_FTNT
Staff
Staff

It is supposed to work. However I hope you are aware that the actual authentication method is Negotiate and therefore it might fall-back to NTLM. Because when FortiGate response back with the proxy-authentication:Negotiate header to client. The client can send back Kerberos token or NTLM token to begin with Negotiate. Both OK. Hints: - NTLM token is much shorter - NTLM token is Base64 encoded and always start with "TlR" while Kerberos starts with "YII"

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors