DEar whome
i have question if i have 2 domain How would mcafee WG know which domain that they need to authen to
1. I have domain A and domain B but i dont know how mcafee select which domain that mwg will choose when user authen to them , trying to use authentication realm to detect but it got blank value
2. Should i use NTLM authen for multi domain or should i use another method. Cant separate by network
Solved! Go to Solution.
Hi,
Hope you are doing well.
Yes you can use NTLM. Below is an recommendeded via of setting up NTLM Authentication when using multiple domains:-
Option here is having one setting, without using default domain value so client give the information in the authentication handshake which domain to use. MWG will use the proper domain then to authenticate.
I set up 2 AD servers one with domain lab.com and other with domain sathram.net as per screenshot attached.
In Windows domain membership you specify domain, so for one I have specified lob.com and for other I have specified sathram.net.
Now their an NTLM negotiation happens between client and MWG wherein in NTLM auth message client sends domain and username information
I have imported NTLM Authentication rule set from rule set library and have created authentication method NTLM in which in default domain name I have left it blank and not specified any domain name as per screenshot attached.
Here we have not specified domain name in NTLM settings and making sue of domain name which client sends in NTLM AUTH message and accordingly MWG will send to that DC server mapped with that domain in Windows domain membership.
I did testing with one user in sathram.net domain and once that user logged in via that domain, MWG only send Auth request to DC server of sathram.net by looking at domain name sent in NTLM AUTH message by client and similarly did testing with one user logged in via domain lab.com and MWG sent AUTH request from client for verification to DC server of lab.com domain only.
Was my reply helpful? If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
Regards
Alok Sarda
Hi,
Hope you are doing well.
Yes you can use NTLM. Below is an recommendeded via of setting up NTLM Authentication when using multiple domains:-
Option here is having one setting, without using default domain value so client give the information in the authentication handshake which domain to use. MWG will use the proper domain then to authenticate.
I set up 2 AD servers one with domain lab.com and other with domain sathram.net as per screenshot attached.
In Windows domain membership you specify domain, so for one I have specified lob.com and for other I have specified sathram.net.
Now their an NTLM negotiation happens between client and MWG wherein in NTLM auth message client sends domain and username information
I have imported NTLM Authentication rule set from rule set library and have created authentication method NTLM in which in default domain name I have left it blank and not specified any domain name as per screenshot attached.
Here we have not specified domain name in NTLM settings and making sue of domain name which client sends in NTLM AUTH message and accordingly MWG will send to that DC server mapped with that domain in Windows domain membership.
I did testing with one user in sathram.net domain and once that user logged in via that domain, MWG only send Auth request to DC server of sathram.net by looking at domain name sent in NTLM AUTH message by client and similarly did testing with one user logged in via domain lab.com and MWG sent AUTH request from client for verification to DC server of lab.com domain only.
Was my reply helpful? If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
Regards
Alok Sarda
Hi,
Adding 2 more screenshot
Regards
Alok Sarda
many many thanks this is exactly what i am looking for
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: