Articles Articles Most Popular Articles Most Popular Articles Most Helpful Articles Most Helpful Articles
DrillDown Icon Table of Contents Back
 . . . . . . . . . . . . .
DrillDown Icon What's New
DrillDown Icon Knowledge Base Information
DrillDown Icon Cyberoam UTM
DrillDown Icon Product Literature
DrillDown Icon Best Practices & Policies
DrillDown Icon Protect Your Cyberoam Appliances from Power Fluctuations
DrillDown Icon Version 10.x
DrillDown Icon Cyberoam Maintenance
DrillDown Icon FAQ's
DrillDown Icon How To
DrillDown Icon Anti Spam
DrillDown Icon Anti Virus
DrillDown Icon Authentication
DrillDown Icon Configure Guest User Authentication
DrillDown Icon Configure Windows Server 2008 as a RADIUS Server with MS-CHAP v2 Authentication
DrillDown Icon Push NTLM Settings in Internet Explorer Through GPO in Windows Server 2008
DrillDown Icon Install Novell eDirectory Compatible CTAS
DrillDown Icon Integrate Cyberoam with RSA SecurID as a RADIUS Client
DrillDown Icon Allow Specific Websites without Authentication
DrillDown Icon Configure NTLM Support in Web Browsers
DrillDown Icon Configure NTLM in Cyberoam
DrillDown Icon Configure Cyberoam to use RADIUS Server for Authentication
DrillDown Icon Customize a Denied Message on Cyberoam Appliance
DrillDown Icon Integrate Cyberoam with LDAP
DrillDown Icon Serve a Denied page instead of Captive Portal for unauthenticated users
DrillDown Icon Implement Clientless SSO Authentication in Multiple Active Directory Domain Controller
DrillDown Icon Assign Group Membership to Users in case of Tight Integration with Active Directory
DrillDown Icon Integrate with Active Directory
DrillDown Icon Implement Clientless SSO Authentication in Single AD Domain Controller Environment
DrillDown Icon Implement SSO Authentication with AD
DrillDown Icon Import AD Groups
DrillDown Icon Implement Single Sign on Authentication with Active Directory Integration with Non-English version of Windows
DrillDown Icon Serve a Denied Page with Captive Portal Link for Unauthenticated Users
DrillDown Icon Clients
DrillDown Icon Content Filtering
DrillDown Icon Firewall
DrillDown Icon Identity-based Policies
DrillDown Icon IPS
DrillDown Icon Logs & Reports
DrillDown Icon Multiple Gateway - Load Balancing and Failover
DrillDown Icon Quality of Service (QoS)
DrillDown Icon Registration
DrillDown Icon Routing
DrillDown Icon SSL VPN
DrillDown Icon System
DrillDown Icon Users and Groups
DrillDown Icon Virtual LANs
DrillDown Icon VPN
DrillDown Icon Web Application Firewall (WAF)
DrillDown Icon Wireless LAN
DrillDown Icon Configure Wireless WAN
DrillDown Icon TroubleShooting
DrillDown Icon Visio Stencils
DrillDown Icon Glossary
DrillDown Icon Product Technical Support
DrillDown Icon Compatibility
DrillDown Icon Cyberoam Virtual UTM
DrillDown Icon Endpoint Data Protection
DrillDown Icon Cyberoam SSL VPN
DrillDown Icon Cyberoam iView
DrillDown Icon Cyberoam Central Console
DrillDown Icon Cyberoam's On-Cloud Management Service
  Email This ArticlePrintPrint Current Article and All Sub-Articles
Rate Icon Rate Icon Rate Icon Rate Icon Rate Icon
 
Configure NTLM in Cyberoam

Applicable Version: 10.02.0 Build 206 onwards

Overview
 
NTLM (NT LAN Manager), also known as Windows Challenge/Response, is a suite of security protocols that offers authentication, integrity and confidentiality to users. It is the authentication protocol used on networks that include systems running the Windows operating system and on stand-alone systems.

NTLM uses an encrypted challenge/response mechanism in which clients are able to get authenticated without sending a password over the wire. Here, credentials consist of a domain name, a user name, and a one-way hash of the user's password obtained via an Interactive Authentication Process. The system requesting authentication must perform a calculation that proves it has access to the secured NTLM credentials.

Scenario
 
Configure Cyberoam to allow authentication of users and user groups using NTLM.


Configuration

NTLM is configured in Cyberoam by following the steps given below. All configurations are to be done from Web Admin Console using “Administrator” profile.

Note:

NTLM is a browser-initiated authentication method. Hence, in Cyberoam, it is at lower priority than other authentication methods like:
 
-       Corporate Client
-       Clientless Single Sign-On
-       Client-based Single Sign-On

NTLM is used as a failback if any of the above authentication methods fail. If NTLM also fails, then the Captive Portal is displayed using which user can authenticate.

Step 1: Integrate Cyberoam with Active Directory

It is required to integrate Cyberoam with Active Directory (AD) to facilitate authentication of users and user groups. For details on how to integrate Cyberoam with Active Directory, refer to "Integrate with Active Directory" in the Related Articles section at the end of this article.

Step 2: Enable NTLM

Go to System à Administration à Appliance Access. Under Authentication Services, enable access of NTLM for the required zones. Here, we have enabled NTLM for LAN zone.
  
 
 
 

Step 3: Configure Firewall Rules

Configure the LAN_WAN_AnyTraffic Rule (Default Rule 1), as shown below, to impose strict authentication.  

 
 

Note:

The above rule will not apply if the user’s first request is an HTTPS request. In such cases, edit the below mentioned parameters of LAN_WAN_AnyTraffic Rule as shown.

 

Parameter

Value

Name

LAN_WAN_AnyTraffic

Zone

Source: Any
Destination: Any

Attach Identity

Disabled

Network/Host

Source: Any
Destination: Any

Services

Any

Schedule

All the time

Action

Accept

Apply NAT

Enabled
MASQ

Web Filter

Deny All

 
 

Step 4: Configure Web Browser to support NTLM

Configure your web browser to allow NTLM Authentication. For details on how to configure your web browser, refer to "Configure NTLM Support in Web Browsers" in the Related Articles section at the end of this article.
 
                                                                                                                                                                          
                                                                                                                                                                                               Document Version: 1.0 – 19/03/2012
Attachments
Related Articles

Article ID: 2251