EFW Support

Support => General Support => Topic started by: denisfm on Friday 19 November 2010, 12:57:27 am



Title: Authenticated proxy - Windows 2003
Post by: denisfm on Friday 19 November 2010, 12:57:27 am
Staff in my environment I have two servers and domain controller, controlling the same domain.

But I have to setup Domain name (pre-Windows 2000)

Example:

Domain: dominio.org.br
Domain name (pre-Windows 2000): dom

In the setting System-> Network-configuratio> Domain Name: "put the long name of the field or pre-windows?"

Proxy-> Authentication-> * Authentication Realm "put the long name of the field or pre-windows?"

Proxy-> Authentication-> Domainname of AD server * "put the long name of the field or pre-windows?"

Every time I login it says the configuration is invalid.
"Failed to join domain: Invalid configuration and configuration modification was not requested"

But when I type the wrong password it comes to query the AD as it asks to have verified the reported data.


Title: Re: Authenticated proxy - Windows 2003
Post by: davvidde on Friday 19 November 2010, 09:17:00 am
As I have configured my installation I put the "Pre-Windows 2000) NetBIOS domain nowhere.
As Active Directory use Kerberos, where you asked for domain name you only need to put on the FQDN.
However EFW does still use NTLM to authenticate so this protocol must be enabled in Domain Controller.

In the setting System-> Network-configuration> Domain Name: dominio.org.br
Proxy-> Authentication-> * Authentication Realm: DOMINIO.ORG.BR
Proxy-> Authentication-> Domainname of AD server: dominio.org.br

This works for me in efw2.4

Davide


Title: Re: Authenticated proxy - Windows 2003
Post by: denisfm on Tuesday 30 November 2010, 02:22:08 am
I changed the file / etc / samba / winbind.conf.tmpl to workgroup = ${NTLM_DOMAIN.upper()}

Thanks,

Denis
Endian Firewall 2.4.0