Solved

Remote Branch Internet Access

Posted on 2007-11-29
3
292 Views
Last Modified: 2012-06-21
Hi, I have an issue with filtering web access from a remote branch through the head office Fortigate 100.  We have 2 Sites with a private link between the two which is managed by BT.  The link is not designed to carry internet traffic so we need to use a proxy server to get net access.  The problem we are having is the when the ISA 2004 proxy forwards the request to the fortigate, the traffic appears from the proxy server and cannot filter based on username/group assignment.  My main question is, is there anyway that the proxy server can forward the username and original ip information onto the fortigate for filtering.....

many thanks
0
Comment
Question by:aztechcomms
3 Comments
 
LVL 18

Accepted Solution

by:
PowerIT earned 500 total points
ID: 20380699
You can give basic authentication forwarding in ISA a try. No garantuee that this will work, but you can't loose...
To do this, open the listener part of the rule and on the preferences tab click the authentication button.
Make sure only 'basic authentication' is selected (remove all other check boxes). Close out and doubleclick the name of the rule and open the users tab. Then enable the checkbox at the bottom for forward basic authentication

I have a similar problem where all traffic originates from one IP and the appliance (NetASQ in our case) can authenticate a user but from then on all traffic seems to be originating from that first authenticated user. That's because once authenticated ALL non ISA appliances I have seen (including Fortinet) track the IP, not the user, when working with AD authentication.
This can only be resolved by doing the filtering on the ISA server, but that would mean adding another filtering package.

J.
0

Featured Post

Courses: Start Training Online With Pros, Today

Brush up on the basics or master the advanced techniques required to earn essential industry certifications, with Courses. Enroll in a course and start learning today. Training topics range from Android App Dev to the Xen Virtualization Platform.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Sonicwall TZ 205- Dropping Incoming E-mail as IP Spoof 13 160
Mac-address sticky 12 54
Setting up new vpn 15 65
non-domain members are not prompted for credentials 18 35
Using in-flight Wi-Fi when you travel? Business travelers beware! In-flight Wi-Fi networks could rip the door right off your digital privacy portal. That’s no joke either, as it might also provide a convenient entrance for bad threat actors.
Phishing is at the top of most security top 10 efforts you should be pursuing in 2016 and beyond. If you don't have phishing incorporated into your Security Awareness Program yet, now is the time. Phishers, and the scams they use, are only going to …
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

815 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now