Endian Knowledge Base
Search:     Advanced search
Browse by category:

Common pitfalls with Active Directory (Windows) authentication configuration with HTTP Proxy

Add comment
Views: 3449
Votes: 0
Comments: 0
Posted: 20 Nov, 2007
by: Warasin P.
Updated: 04 Dec, 2008
by: Admin A.
Using the Windows Authentication, there are a number of pitfall's, which need to pay attention. Those are due to Kerberos authentication, which is not as low-maintenance as it should be.

There is a screencast for version 2.1.

The steps you should take care of are:
  • Both, the Active Directory Server and the Endian Firewall need to have exactly the same time.
    Sync the AD from Endian Firewall using NTP or contrarywise.


  • Endian Firewall need to be able to resolve SRV records from the AD. Therefore with versions
    • prior to version 2.2 it is necessary to configure the PDC as nameserver for the Endian Firewall.
      You do this by configuring it with the Network Wizard.
      Remember to setup the ISP's nameservers on the AD!
    • starting with version 2.2 you need to configure the PDC as nameserver for your Active Directory domain using "Proxy > DNS > Custom nameserver".


  • The PDC hostname, which you configure within "Common domain settings" in "Proxy > HTTP > Authentication" must be known by the Endian Firewall.
    If it is not resolvable anyway through DNS, you need to configure it within "Network > Edit Hosts" and make it point to the PDC's ip address.


  • The "Authentication Realm Prompt", which you can configure within "Proxy > HTTP > Authentication" need to be the Fully Qualified Domain Name used by the AD.
Also read
document HTTP Proxy gives "Error fetching group names" when downloading groups from the Windows Active Directory
document How to configuer dansguardian white- /blacklists?
document How to configure domains without http authentication?
document How to configure the HTTP Antivirus whitelist?

Others in this Category
document How to configure domains without http authentication?
document How to configure the HTTP Antivirus whitelist?
document HTTP Proxy gives "Error fetching group names" when downloading groups from the Windows Active Directory
document How to use POP3s?
document Why is whitelist not working with http proxy authentication / contentfilter / antivirus?
document Can I train the Antispam Engine?
document IPSEC to Linksys RV042 VPN How-to
document How to exclude specific sites from content filter?
document Why do some internet based games and applications fail to connect behind Endian Firewall?
document Why does the Windows update not work with HTTP Proxy on?
document How can I make my Browsers automatically use the Endian Firewall HTTP Proxy in non-transparent mode?
document How can I forward spam mail to a specific email address?
document My VPN Firewall does not filter my connections between my Roadwarriors !? OR on newer versions: My roadwarriors cannot see each other!?
document OpenVPN does not push routing information to clients after i changed some
document Why do the proxy graphs not work?
document SMTP Proxy: Mail for xxx loops back to myself. How to solve?
document How do I configure the OpenVPN client on a Linux workstation?
document How to block specific web sites?
document How do I configure the OpenVPN client on a Windows workstation?
document How to configuer dansguardian white- /blacklists?
» More articles



RSS