I would like to ask somebody, is it possible in fortigate 5.6.x setting explicit proxy with kerberos on AD authentication , when is disabled ip-based authentication? I need have in a log written which user which web site open. Kerberos i need because i do not want use ntlm.
It is supposed to work. However I hope you are aware that the actual authentication method is Negotiate and therefore it might fall-back to NTLM. Because when FortiGate response back with the proxy-authentication:Negotiate header to client. The client can send back Kerberos token or NTLM token to begin with Negotiate. Both OK. Hints: - NTLM token is much shorter - NTLM token is Base64 encoded and always start with "TlR" while Kerberos starts with "YII"
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
User | Count |
---|---|
2534 | |
1351 | |
795 | |
641 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.