Agentless NTLM support
Agentless NTLM authentication can be configured directly from the FortiProxy unit to the Domain Controller using the SMB protocol (no agent is required).
NOTE: This authentication method is only supported for proxy policies.
Syntax
NOTE: The set domain-controller
command is only available when method
is set to ntlm
and/or negotiate-ntlm
is set to enable
.
config authentication scheme
edit <name>
set method ntlm
set domain-controller <dc-setting>
next
end
config user domain-controller
edit <name>
set ip-address <dc-ip>
set port <port> // The default is 445.
set domain-name <dns-name>
set ldap-server <name>
next
end