Solved

Transparent firewall authentication of Windows client through Juniper SSG

Posted on 2011-02-16
3
1,052 Views
Last Modified: 2012-05-11
We are currently switching from an MS ISA firewall to a Juniper SSG.  One nice feature of ISA is that it's integrated with Active Directory, meaning it's very easy to create firewall access rules that are dependent on AD groups.  For example, only users that are members of the AD group FTPUsers are allowed to use FTP through the ISA.

I am attempting to migrate a few of these group-dependent rules over to the Juniper.  I have managed to configure MS Network Policy Server as the RADIUS server which the Juniper uses for authentication.  This works for authenticating users.  However, they are prompted for credentials when attempting to use a protocol whose Juniper rule is group-dependent.

Does anyone know of a way that the Windows clients could pass the credentials of the logged-on user - via RADIUS - to the Juniper when prompted?

It would go something like this:
Windows client requests use of a protocol through the Juniper -->
<-- Juniper queries for user credentials
Windows client provides credentials of currently logged-on user -->
Juniper authenticates user via RADIUS and provides access, if the user is a member of the relevant group

In short, it's going to be cumbersome for my users if they are required to enter credentials any time that they wish to use a group-dependent protocol through the Juniper.  I've contacted Juniper support, and they're pointing back to the Windows client as the mechanism for solving this issue.  Thank you for your assistance.
0
Comment
Question by:sloth10k
3 Comments
 
LVL 18

Accepted Solution

by:
deimark earned 500 total points
ID: 34911751
In short, juniper support are correct, the client is the best way to maintain this sign credentials and also pass them on when requested

Sadly, the SSG cannot manage any of this single sign on ( SSO)

However, Juniper do have a very good SSL VPN device, the SA series, that integrates really well into AD and also manages the SSO well too.  It is of course another device but it is the market leader for providing remote access solutions
0
 
LVL 33

Expert Comment

by:digitap
ID: 35187478
This question has been classified as abandoned and is being closed as part of the Cleanup Program. See my comment at the end of the question for more details.
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Sonicwall NSA240 AppFlow 2 75
ADMT Intra Forest migration questions 7 124
Group Policy Question 7 61
Strange routing problem between subnets 2 78
This is a little timesaver I have been using for setting up Microsoft Small Business Server (SBS) in the simplest possible way. It may not be appropriate for every customer. However, when you get a situation where the person who owns the server is i…
The password reset disk is often mentioned as the best solution to deal with the lost Windows password problem. In Windows 2008, 7, Vista and XP, a password reset disk can be easily created. But besides Windows 7/Vista/XP, Windows Server 2008 and ot…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

914 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now