Forum Discussion

Niels_van_Slui1's avatar
Niels_van_Slui1
Icon for Altostratus rankAltostratus
Feb 04, 2019

SWG, Kerberos Auth and Identify users by credentials

When building a SWG explicit forward proxy it is possible to identify users by IP address or by credentials. About identification by credentials, the F5 documentation says:

 

When you choose to identify users by credentials, SWG maintains an internal mapping of credentials to sessions. To support this choice, you need an NTLM Auth Configuration object and you should check the result of NTLM authentication in the access policy.

 

Does this imply that identification by credentials does not work when using Kerberos Auth?

 

2 Replies

  • Unfortunately I'm still looking for the answer to this question. To give some more context regarding this question, in my lab I've configured a LTM + APM Explict Forward Proxy that is configured to use Kerberos Authentication. And this works as expected. Users are authenticated via Kerberos and can access the internet by using the proxy. However, I've noticed that when there are multiple unique users on a shared system (like a windows terminal server), only one user is actually authenticated and all the other subsequent users on the system are not authentiated, but are given access via the proxy. It seems that when a user succesfully authenticates, access is granted to the users source IP address.

     

    I'm trying to find out if this is a known limitation of using Kerberos Authentication in combination with an explicit forward proxy on the F5 BIG-IP or that I'm missing something in my configuration.