Welcome, Guest. Please login or register.
Did you miss your activation email?
Wednesday 30 October 2024, 06:22:58 pm

Login with username, password and session length

The Latest Endian Firewall is now available for download HERE
14248 Posts in 4376 Topics by 6515 Members
Latest Member: hulteends
Search:     Advanced search
+  EFW Support
|-+  Support
| |-+  EFW SMTP, HTTP, SIP, FTP Proxy Support
| | |-+  User name not showing up for NTLM/AD Joined Auth in Logs
0 Members and 5 Guests are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: User name not showing up for NTLM/AD Joined Auth in Logs  (Read 15349 times)
jfinnigan
Jr. Member
*
Offline Offline

Gender: Male
Posts: 4

Network Administrator


« on: Saturday 26 October 2013, 02:33:56 am »

I'm using Edian as a proxy server only (non-transparent and not using it as a router)

It's using NTLM Auth and It is joined to the domain. SSO with the proxy works fine on windows 7 (and my test windows 8 machine)

However the logs never say the user name of the person who got a blocked page  It shows the date 127.0.0.1 then the users actual IP followed by the denied page url.
the Blocked page only shows 127.0.0.1 where the -User flag is at. How do I get it to show there A/D username instead of the loopback ip?

Thanks,
Jason
Logged
jfinnigan
Jr. Member
*
Offline Offline

Gender: Male
Posts: 4

Network Administrator


« Reply #1 on: Saturday 26 October 2013, 05:28:52 am »

Update:

I did look in the squid Access logs (/var/log/squid.log) and the usernames show their so why don't they in the dansgurdian logs on EFW webgui?

The odd thing is in the denied entries no username appears, but in the TCP_MISS Entrties they do.
Logged
Pages: [1] Go Up Print 
« previous next »
Jump to:  

Page created in 0.036 seconds with 18 queries.
Powered by SMF 1.1 RC2 | SMF © 2001-2005, Lewis Media Design by 7dana.com