Virtual Secure Web Gateway

 View Only
  • 1.  error! NTLM HTTP 407 failed test: A system error occurred.

    Posted Apr 30, 2011 01:00 AM
      |   view attached

    Hi everyone,

    I have problems to authenticate users who are not in the domain.The best way is to authenticate on the proxy to enable or web browsing.

    It set up a Symantec Web Gateway 5.0.142 INLINE + PROXY Mode with NTLM integration.

    The allocation of filtering policies to different OUs, users and range of IPs are assigned correctly.

    But to strengthen the authentication with authentication policy, this does not work for PCs that are not within the domain.

    In no time, all users are seeking their window displays with your user authentication domain, providing access but applying policies.

    The biggest problem is with the PCs that are not in the domain, which are external auditors which are restricted from accessing network resources.

    While in these IPs reports appear, as well as all authenticated users' browsing, the greater concern is that they are requesting authentication.

    By testing the NTLM settings within Administration> Configuration> Authentication> NTLM Test (HTTP 401), confirms that there is successful communication with the LDAP server, but when you click on the authentication test, it can not resolve the URLhttp:/ /PROXYWAN:20200/ntlm/authenticate.php?.

    PROXYWAN is the name that was assigned to Inline Interface, which created a DNS record to point at the IP address 172.22.104.22.Similarly the problem persists.

    NSLOOKUP was conducted to PROXYWAN and resolves without problems.

    When you click the Test button NTLM (Proxy 407), the error!NTLM HTTP 407 test failed: A system error occurred.

    Some of you may have idea where the problem come?
    Attached are some pictures ..

    Any response is welcome! :)

    PS: I know that this version is still beta and this I have to post in the appropriate forum (which also was posted), but as due to a generic error, it may be that someone has passed the same with the version 4.5 . x.

    Attachment(s)

    pdf
    SWG 5.0.142 NTLM Issue.pdf   714 KB 1 version


  • 2.  RE: error! NTLM HTTP 407 failed test: A system error occurred.

    Posted May 10, 2011 01:37 AM

    I learnt DEV has already reached you through e-mail about this problem.

     

    Regards,
    Dash



  • 3.  RE: error! NTLM HTTP 407 failed test: A system error occurred.

    Posted May 13, 2011 07:29 PM


    Thanks for your response. As you said, this was already resolved by the DEV team.

    Thanks!



  • 4.  RE: error! NTLM HTTP 407 failed test: A system error occurred.
    Best Answer

    Posted Jul 15, 2011 09:14 PM

    To leave this issue resolved, I published the solution we found with DEV.

    The main problem is that while NTLM authentication for the 401 just need a domain user who has read perms for the NTLM 407 is necessary to enter a user with DomainAdmin.

    It is advisable to create a unique user account for this transaction and is used by SWG, to not use a real user. Thus, as we all know we can fall into the risk of errors authentificacion again because it made ​​the change of password in LDAP and not in SWG.