McAfee MAP-3300-SWG Product Guide - Page 250

Virtual Hosting, Enable Integrated Windows Authentication requires restart

Page 250 highlights

Overview of System features Virtual Hosting 7 Configure the appliance to use Kerberos Authentication (Add a group). a In the navigation bar, select System | Users, groups and Services | Web user authentication. b Under User Authentication Services, click Add a group. Type the Group name, for example, kerberos-group. Select the kerberos-service for this group and click OK. c Click the green checkmark to apply the changes. d Select Web | Web Configuration | HTTP | Connection Settings. e Under User Authentication, select Enable user authentication. f Select the Kerberos group, and click the green checkmark to apply the changes. 8 Configure the clients to use the appliance as a proxy server. Make the following configuration changes in Internet Explorer on each client to redirect the browsers/workstations to the appliance: a Open Internet Explorer and select Tools, Internet Options. b Click the Connections tab, then click LAN Settings. Type the IP address and the port for the appliance. c Click Advanced, add the FQDN of the appliance to the exception list, and click OK. d Click the Security tab, select Local Intranet, and click Sites. e Click Advanced and add the FQDN of the appliance to this zone. Click OK, then click Custom Level and select Automatic logon only in Intranet Zone, and click OK. (The option is at the end of the scrolling list.) f Click the Advanced tab, select Enable Integrated Windows Authentication (requires restart), then click OK (The option is near the end of the scrolling list.) g Close and open the browser again. Try to access a website. If you are logged on to the domain, the page opens successfully. If you are not logged on the Active Directory domain (for instance, logged on locally or if using a Macintosh or Linux system), the following error is displayed on the page: 401 error SCM Appliance Request for authentication Requesting authentication for kerberos-group kerberos-service, type Kerberos kerberos-group kerberos-service Virtual Hosting Use these topics to gain an understanding of the options within the virtual hosting pages. You can configure the virtual hosts and virtual networks that the appliance needs to scan. Contents Virtual Hosts Virtual Networks Virtual Hosts Use this page to add, edit, or delete virtual hosts and show available virtual hosts. System | Virtual Hosting | Virtual Hosts 250 McAfee Email and Web Security Appliances 5.6.0 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

7
Configure the appliance to use Kerberos Authentication (Add a group).
a
In the navigation bar, select
System
|
Users, groups and Services
|
Web user authentication
.
b
Under
User Authentication Services
, click
Add a group
. Type the
Group name
, for example, kerberos-group.
Select the kerberos-service for this group and click
OK
.
c
Click the green checkmark to apply the changes.
d
Select
Web
|
Web Configuration
|
HTTP
|
Connection Settings
.
e
Under
User Authentication
, select
Enable user authentication
.
f
Select the Kerberos group, and click the green checkmark to apply the changes.
8
Configure the clients to use the appliance as a proxy server. Make the following configuration
changes in Internet Explorer on each client to redirect the browsers/workstations to the appliance:
a
Open Internet Explorer and select
Tools, Internet Options
.
b
Click the
Connections
tab, then click
LAN Settings
. Type the IP address and the port for the appliance.
c
Click
Advanced
, add the FQDN of the appliance to the exception list, and click
OK
.
d
Click the
Security
tab, select
Local Intranet
, and click
Sites
.
e
Click
Advanced
and add the FQDN of the appliance to this zone. Click
OK
, then click
Custom Level
and select
Automatic logon only in Intranet Zone
, and click
OK
. (The option is at the end of the scrolling
list.)
f
Click the
Advanced
tab, select
Enable Integrated Windows Authentication (requires restart)
, then click
OK
(The
option is near the end of the scrolling list.)
g
Close and open the browser again. Try to access a website. If you are logged on to the domain,
the page opens successfully. If you are not logged on the Active Directory domain (for instance,
logged on locally or if using a Macintosh or Linux system), the following error is displayed on the
page:
401 error SCM Appliance <domain> Request for authentication Requesting authentication for
kerberos-group kerberos-service, type Kerberos kerberos-group kerberos-service
Virtual Hosting
Use these topics to gain an understanding of the options within the virtual hosting pages.
You can configure the virtual hosts and virtual networks that the appliance needs to scan.
Contents
Virtual Hosts
Virtual Networks
Virtual Hosts
Use this page to add, edit, or delete virtual hosts and show available virtual hosts.
System
|
Virtual Hosting
|
Virtual Hosts
Overview of System features
Virtual Hosting
250
McAfee Email and Web Security Appliances 5.6.0 Product Guide