Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense member AD 2012 R2

    General pfSense Questions
    3
    10
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      ricardodru
      last edited by

      Dear,

      It is possible to cause the pfsense 2.2.5 amd64 is a member of a Windows 2012 R2 domain?

      Objective:
      I must deploy squid + squidguard, authenticated by groups in AD.
      But I wish, when the User browses the Internet, the pfsense not solicit login + password, but get session information of the logged User in windows.

      Someone could indicate some tutorial?
      Thank you!

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        No. Firewall's a completely horrible place for Samba + Kerberos junk.

        1 Reply Last reply Reply Quote 0
        • R
          ricardodru
          last edited by

          @doktornotor:

          No. Firewall's a completely horrible place for Samba + Kerberos junk.

          Thanks for the feedback.

          My scenario: pfSense 2.2.5 amd64, Squid, squidGuard and Windows Server 2012 R2

          In this case, it is possible to authenticate the pfsense in AD 2012 R2?
          I would like to deploy SquidGuard authenticated, performing locks / release by Access Group in AD.

          1 Reply Last reply Reply Quote 0
          • D
            doktornotor Banned
            last edited by

            Not with NTLM, no. As said, that requires Samba installed on firewall (will never happen).

            1 Reply Last reply Reply Quote 0
            • R
              ricardodru
              last edited by

              @doktornotor:

              Not with NTLM, no. As said, that requires Samba installed on firewall (will never happen).

              For the version I'm using the pfsense 2.2.5, it is possible to install samba to perform entry into active diretory?

              1 Reply Last reply Reply Quote 0
              • H
                heper
                last edited by

                dont install samba

                https://forum.pfsense.org/index.php?topic=87772.msg571885#msg571885

                1 Reply Last reply Reply Quote 0
                • D
                  doktornotor Banned
                  last edited by

                  @heper:

                  dont install samba
                  https://forum.pfsense.org/index.php?topic=87772.msg571885#msg571885

                  LDAP and NTLM are two completely different things…

                  1 Reply Last reply Reply Quote 0
                  • H
                    heper
                    last edited by

                    @doktornotor:

                    @heper:

                    dont install samba
                    https://forum.pfsense.org/index.php?topic=87772.msg571885#msg571885

                    LDAP and NTLM are two completely different things…

                    true but afaik OP doesnt need ntlm, OP wants:

                    I would like to deploy SquidGuard authenticated, performing locks / release by Access Group in AD.

                    1 Reply Last reply Reply Quote 0
                    • D
                      doktornotor Banned
                      last edited by

                      Yeah, but

                      But I wish, when the User browses the Internet, the pfsense not solicit login + password, but get session information of the logged User in windows.

                      1 Reply Last reply Reply Quote 0
                      • R
                        ricardodru
                        last edited by

                        If I use the ldap option, the User will be required to enter login / password to browse.
                        NTLM takes the User section, requiring no login / password.

                        Thank help everyone.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.