30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

User Authentication<br />

Redirection to the authentication page<br />

If the Always require users to be authenticated when accessing web pages option is<br />

enabled, user authentication will be required for access to any website (unless the user is<br />

already authenticated). The method of the authentication request depends on the method<br />

used by the particular browser to connect to the Internet:<br />

• Direct access — the browser will be automatically redirected to the authentication<br />

page of the <strong>Kerio</strong> Control’s web interface (see chapter 12.2) and, if the<br />

authentication is successful, to the solicited web page.<br />

• <strong>Kerio</strong> Control proxy server — the browser displays the authentication dialog and<br />

then, if the authentication is successful, it opens the solicited web page.<br />

If the Always require users to be authenticated when accessing web pages option is<br />

disabled, user authentication will be required only for Web pages which are not available<br />

(are denied by URL rules) to unauthenticated users (refer to chapter 13.2).<br />

Note: User authentication is used both for accessing a Web page (or/and other services)<br />

and for monitoring of activities of individual users (the Internet is not anonymous).<br />

Force non-transparent proxy server authentication<br />

Under usual circumstances, a user connected to the firewall from a particular computer<br />

is considered as authenticated by the IP address of the host until the moment when<br />

they log out manually or are logged out automatically for inactivity. However, if the<br />

client station allows multiple users connected to the computer at a moment (e.g. Microsoft<br />

Terminal Services, Citrix Presentation Server orFast user switching on Windows<br />

XP, Windows Server 2003, Windows Vista and Windows Server 2008), the firewall requires<br />

authentication only from the user who starts to work on the host as the first. The other<br />

users will be authenticated as this user.<br />

In case of HTTP and HTTPS, this technical obstruction can be passed by. In web browsers<br />

of all clients of the multi-user system, set connection to the Internet via the <strong>Kerio</strong> Control’s<br />

proxy server (for details, see chapter 9.4), and enable the Enable non-transparent proxy<br />

server option in <strong>Kerio</strong> Control. The proxy server will require authentication for each new<br />

session of the particular browser. 6 .<br />

Forcing user authentication on the proxy server for initiation of each session may<br />

bother users working on “single-user” hosts. Therefore, it is desirable to force such<br />

authentication only for hosts used by multiple users. For this purpose, you can use the<br />

Apply only for these IP addresses option.<br />

Automatic authentication (NTLM)<br />

If the Enable user authentication automatically... option is checked and Internet Explorer<br />

or Firefox/SeaMonkey is used, it is possible to authenticate the user automatically using<br />

the NTLM method.<br />

This means that the browser does not require username and password and simply uses<br />

the identity of the first user connected to Windows. However, the NTLM method is not<br />

6 Session is every single period during which a browser is running. For example, in case of Internet Explorer, Firefox and<br />

Opera, a session is terminated whenever all windows and tabs of the browser are closed, while in case of SeaMonkey,<br />

a session is not closed unless the Quick Launch program is stopped (an icon is displayed in the toolbar’s notification<br />

area when the program is running).<br />

162

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!