Jump to:navigation, search
Wiki






































HTTP proxy authentication guide

Last adaptation to the version: 14.1.1(11.2025)

New:
  • Anpassung an die neuen HTTP Proxy Profile
  • Updated to Redesign of the webinterface
notempty
This article refers to a Beta version
Access: UTM-IP:Port or UTM-URL:Port
Port as configured at Network / Appliance Settings / Webserver
Default-Port: 11115
i.e.: https://utm.ttt-point.de:11115
Default: https://192.168.175.1:11115
Applications HTTP Proxy


User authentication on the HTTP proxy

In addition to the transparent mode of the HTTP proxy, it is also possible to require users to authenticate themselves before using the Internet.

This authentication can be performed either against the UTM user management or an authentication server such as Active Directory, LDAP, or Radius.

Requirements for authentication on the HTTP proxy:

  • The proxy has been entered in the browser
  • The packet filter settings have been adjusted accordingly


Proxy setting in the browser

Proxy configuration in the browser, here in Mozilla Firefox

In the connection settings of the used browser, the IP address of the corresponding interface of the UTM can be entered under Manual proxy configuration.

In addition, the port must be entered, which is set in the UTM under Applications HTTP Proxy .

notempty
New as of v14.1.1
This can be done either in the global profile or an optional additional profile. When the UTM is delivered, this is port 8080.



Packet filter settings

Call in menu Firewall Packet Filter

The UTM is shipped with a packet filter rule set to allow access from the internal network to the Internet with all services (any).

Users could potentially change the browser's proxy settings to bypass authentication.
Therefore,

  • this rule should be “disabled” or, alternatively,
  • a corresponding service group should be created for this rule that replaces any

# Source Destination Service NAT Action Active Package Filter UTMuser@firewall.name.fqdnFirewall Package Filter Log Update rules Package Filter settings for HTTP proxy authentication
internal-network internet any HN Accept Off
internal-network internal-interface proxy Accept On

More information on the packet filter rules can be found here.




Authentication via the user management of the UTM

Create proxy user group

Call in menu Authentication User

Groups
User UTMuser@firewall.name.fqdnAuthentication 42 Benutzergruppe hinzufügen
Add group Click on the Add group button to create a user group
Caption Value Description Add group UTMuser@firewall.name.fqdnAuthenticationUser Create user group
Group name: Proxy-Group Choose a unique group name
  • No blank space may be used.
  • HTTP-Proxy: On Enable HTTP proxy function
    Save and close Saves the settings and closes the dialog
  • Additional groups are created if different proxy users are to be treated differently.
  • Create user

    User
    User UTMuser@firewall.name.fqdnAuthentication 42 Add user
    Add user Click on the Add user button. A new dialog box opens.
    Login name: User1 Assign login name Add user UTMuser@firewall.name.fqdnAuthenticationUser Edit group and enable HTTP proxy
    Password: ••••••••••••••••••• Assign a secure password
    Expiration date 2028-01-05 00:00:00 Optional: Specify when the password should expire
    Confirm password: ••••••••••••••••••• Re-enter password
    Groups: »Proxy-Group Select pre-set group
    Save and close Saves the settings and closes the dialog
    This process must be repeated for each user that is to be created.
    More information about user management can be found here.

    Enable authentication in HTTP proxy

    Call in menu Applications HTTP Proxy
    notempty
    New as of v14.1.1
    Selecting the profile. Here, you can either select the default profile global or another profile that you have created yourself
    HTTP Proxy UTMuser@firewall.name.fqdnApplications HTTP-Proxy Log 42 Selection of the HTTP proxy profile
    Authentication method: Basic Select method in drop-down menu Edit (global) configurationprofile UTMuser@firewall.name.fqdnApplicationsHTTP Proxy Authentication method "Basic"
    Save Saves the settings
    If now a browser (prepared as above) is started, an authentication prompt appears before the first web page that is called is displayed.
    Authentication prompt

    Authentication with Active Directory

    Call in menu Network Appliance Settings

    DNS-Server

    First, make sure that the UTM can find the domain. To do this, enter the localhost IP address
    Appliance Settings UTMuser@firewall.name.fqdnNetwork 42 Enter localhost IP address
    Primary name server: 127.0.0.1 Enter localhost IP address
    Save Saves the settings
    Call in menu Applications Name Server

    Zones

    Add Relay Zone Then Applications Nameserver  Area Zones button Add Relay Zone must be called to create a new relay zone with the local domain and the IP address of the domain controller. Name Server UTMuser@firewall.name.fqdnApplications 42 Click on the Add Relay Zone button.
    Zone name: securepoint.local Select zone name Add Relay Zone UTMuser@firewall.name.fqdnApplicationsName Server Add Relay Zone
    Type: Relay Select Relay type
    + Add server Click on the button. A new dialog box opens
    IP address: 192.168.175.5 Enter IP address Add server UTMuser@firewall.name.fqdnApplicationsName ServerAdd Relay Zone Add Server
    Port: 53 Select DNS port.
    Default: 53. If you do not specify a port, port 53 is set automatically.
    Save and close Saves the settings and closes the dialog
    Save and close Clicking the button saves the settings for the server.
    The relay zone server securepoint.local has been created Add Relay Zone UTMuser@firewall.name.fqdnApplicationsName Server The relay zone server securepoint.local

    Connecting UTM to Active Directory

    Call in menu Authentication AD/LDAP Authentication
    Assistent Clicking the button starts the wizard.
    Step 1: Directory type
    Directory type: AD - Active Directory Select the Active Directory AD/LDAP Authentication Wizard UTMuser@firewall.name.fqdnAuthenticationAD/LDAP Authentication AD/LDAP Authentication Wizard Step 1
    Next Continue to step 2
    Step 2: Settings
    IP or Hostname: »ldap.ttt-point.de Choose name
  • The address must be adapted to the local environment!
  • AD/LDAP Authentication Wizard Step 2
    Domain: securepoint.local Register domain
    Workgroup: securepoint Preset
    Appliance Account: UTM Preset
    Next Continue to step 3
    Step 3: Nameserver
    If this step has already been done, then the IP address is already preset.
    If not, the IP address can be entered via + Add Server.
    AD/LDAP Authentication Wizard Step 3
    Next Continue to step 4
    Step 4: Join
    Administrator name: Administrator Choose name
    AD/LDAP Authentication Wizard Step 4
    Password: ••••••••••••••••••• Assign a secure password
    Done Completes the process
    Status
    Connection status: The connection has been successfully established AD/LDAP Authentication UTMuser@firewall.name.fqdnAuthentication Wizard AD/LDAP Authentication Completed

    Create proxy user group for Active Directory

    User UTMuser@firewall.name.fqdnAuthentication 42 Benutzergruppe hinzufügen
    Add group Click on the Add group button to create a user group
    Group name: Proxy-Group Choose a unique group name
  • No blank space may be used.
  • Add group UTMuser@firewall.name.fqdnAuthenticationUser
    HTTP-Proxy: On Enable HTTP proxy function
    Save and close Saves the settings and closes the dialog
  • Additional groups are created if different proxy users are to be treated differently.
  • Enable authentication in HTTP proxy for Active Directory

    Call in menu Applications HTTP Proxy

    Selecting the profile. Here, you can either select the default profile global or another profile that you have created yourself HTTP Proxy UTMuser@firewall.name.fqdnApplications HTTP-Proxy Log 42 Selection of the HTTP proxy profile
    General
  • Authentication at the proxy is only possible if the authentication method is set to NTLM/Kerberos
  • Edit (global) configurationprofile UTMuser@firewall.name.fqdnApplicationsHTTP Proxy Authentication method NTLM/Kerberos
    Authentication method: NTLM/Kerberos Select method in drop-down menu
    Save Saves the settings

    The NTLM authentication method has the advantage that the proxy no longer asks for the username and password when the web browser is opened.

    In this case, authentication is already performed when the operating system is started with the login to the domain.