Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Authenticated transparent proxy

    Scheduled Pinned Locked Moved Cache/Proxy
    1 Posts 1 Posters 794 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      KyferEz
      last edited by

      So I have read in these forums that "it isn't possible" to do transparent authenticated proxying. This is in fact wrong. There is a way, and I know it is possible because Sophos UTM does it and I am going to give you what little I know of how it works so pfSense can look into it.

      1. Listen for the authentication using a "magic IP" of 1.1.1.1. This address is commonly used for special services such as wireless controller management so is unusable by any actual internet routing.
      2. PCs must have fwhostname.mydomain.ext entered in IE as a local intranet zone or the computer fails to authenticate using NTLM.

      What you see when doing this is the browser redirect to the hostname above, use NTLM to authenticate with the firewall, and then the browser is sent to the originally requested page.

      Why am I telling pfSense this? I would LOVE to see better integration and easier management of proxying and content controls enabled in pfSense. As it stands it's just way too difficult to get working and when managing numerous clients is way too difficult to support and provide the filtering solutions and troubleshoot filtering issues.

      Thanks!

      Home Lab:
      Dell r310 Quad core 32GB RAM & 4 3TB SAS
      Intel Server 2 Quad core 24GB RAM & 6 2TB SAS
      Dell r410 Dual Hex core 24GB RAM & 4 1TB SAS
      HP Proliant DL380 Gen7 2 Quad core 24GB RAM & 6 1TB SAS
      28port POE Gb Cisco SG300-28P
      24port POE Gb Managed Netgear
      24port Catalyst Switch
      Cicso 1900 router
      OPNsense
      Sophos UTM
      6 NetScaler VPX3000
      2 VOIP phones Cisco SPA500
      Cisco Air SAP1602 AP

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.