• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Authenticated transparent proxy

Scheduled Pinned Locked Moved Cache/Proxy
1 Posts 1 Posters 843 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K Offline
    KyferEz
    last edited by Feb 28, 2016, 6:16 PM

    So I have read in these forums that "it isn't possible" to do transparent authenticated proxying. This is in fact wrong. There is a way, and I know it is possible because Sophos UTM does it and I am going to give you what little I know of how it works so pfSense can look into it.

    1. Listen for the authentication using a "magic IP" of 1.1.1.1. This address is commonly used for special services such as wireless controller management so is unusable by any actual internet routing.
    2. PCs must have fwhostname.mydomain.ext entered in IE as a local intranet zone or the computer fails to authenticate using NTLM.

    What you see when doing this is the browser redirect to the hostname above, use NTLM to authenticate with the firewall, and then the browser is sent to the originally requested page.

    Why am I telling pfSense this? I would LOVE to see better integration and easier management of proxying and content controls enabled in pfSense. As it stands it's just way too difficult to get working and when managing numerous clients is way too difficult to support and provide the filtering solutions and troubleshoot filtering issues.

    Thanks!

    Home Lab:
    Dell r310 Quad core 32GB RAM & 4 3TB SAS
    Intel Server 2 Quad core 24GB RAM & 6 2TB SAS
    Dell r410 Dual Hex core 24GB RAM & 4 1TB SAS
    HP Proliant DL380 Gen7 2 Quad core 24GB RAM & 6 1TB SAS
    28port POE Gb Cisco SG300-28P
    24port POE Gb Managed Netgear
    24port Catalyst Switch
    Cicso 1900 router
    OPNsense
    Sophos UTM
    6 NetScaler VPX3000
    2 VOIP phones Cisco SPA500
    Cisco Air SAP1602 AP

    1 Reply Last reply Reply Quote 0
    1 out of 1
    • First post
      1/1
      Last post
    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
      This community forum collects and processes your personal information.
      consent.not_received