Hi, I'm looking to turn off NTLM in our domain as a general security improvement. I suspect this will affect our current Fortigate client auth setup though. I'm wondering whether it's possible to reconfigure the Fortigate setup to not rely on NTLM at all, or NTLM v2 only.
We are a secondary school with a 600C on v5.6.8 at the edge of a Windows domain and a separate wifi BYOD VLan. The Windows domain has 2 DCs and about 300 Windows 7 & 10 clients. One of the DCs runs the FSSO collector agent in polling mode.
The wifi VLan clients use Fortigate RADIUS back to Windows NPS running on the 2nd DC. It seems this relies on passthrough NTLM? I'm guessing NTLM is used here because not all clients will be capable of Kerberos?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1720 | |
1094 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.