Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    AD Integration to Pfsense (With NTLM Authentication)

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    4 Posts 2 Posters 6.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Y
      yasanthau
      last edited by

      Hi,

      I'm trying to setup a Pfsense firewall and Squid proxy server with Windows Active Directory integration (ntlm authentication). Can somebody point me to a proper documentation where it explains all the steps required to authenticate users against Windows AD and what kind of security permissions should be allowed from AD to complete the bind process. When we do testing, some windows server versions allow binding with pfsense server whereas some servers does not allow.

      I hope to configure acls (ACL) based on domain user groups. I followed steps given in the link (http://pf2ad.mundounix.com.br/en/index.html), but it does not work at all. Just after getting authenticated, it allows users to browse internet regardless of group acl configuration in SquidGuard Proxy Filter.

      Thanks in advance,

      Yasantha

      1 Reply Last reply Reply Quote 0
      • C
        chris4916
        last edited by

        I never tried to implement NTLM but, thinking about this, I wonder how this works.
        Authentication is pretty clear but then how would you get the group membership information relying on NTLM?

        As you have AD as a back-end, why don't you use LDAP protocol which will bring both authentication and group membership?

        Jah Olela Wembo: Les mots se muent en maux quand ils indisposent, agressent ou blessent.

        1 Reply Last reply Reply Quote 0
        • Y
          yasanthau
          last edited by

          Thank you very much. When I search through the forum, I observed that there are so many posts relating to squid to LDAP integration without answers. I really appreciate if you can point me to a how to documentation or tutorial on the net.

          When using ntlm authentication, we can use winbind to get group membership details. But it doesn't work with SquidGuard ACLs.

          1 Reply Last reply Reply Quote 0
          • C
            chris4916
            last edited by

            Winbind will, somehow, encapsulate LDAP requests, although with some side effects (due to caching if I understand well) especially with group membership.

            This said, rather than looking for "how to", why not explaining more in detail what works and what doesn't in your configuration?
            I believe it will be much more efficient than asking for yet another documentation that you will follow but which may not fix issue you're facing.

            Jah Olela Wembo: Les mots se muent en maux quand ils indisposent, agressent ou blessent.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.