![Juniper NETWORK AND SECURITY MANAGER Manual Download Page 239](http://html1.mh-extra.com/html/juniper/network-and-security-manager/network-and-security-manager_manual_2032862239.webp)
Table 59: Configuring Basic, NTLM, and Kerberos Resources
(continued)
Your Action
Options
Enter the account username. If you select
Variable
as the credential type, you can
enter the username token.
Username
Enter an account password.
Password
Enter the password token if you select
Variable
as the credential type.
Variable Password
Enter the hostnames mapped to the Kerberos realm. You can enter wildcard
characters, such as *.y.com, *.kerber.net, or *.*.
Pattern
Related
Documentation
Defining a Basic Authentication, NTLM, or Kerberos Intermediation Resource Policy
(NSM Procedure) on page 221
•
•
Configuring a SAML Access Control Resource Policy (NSM Procedure) on page 223
•
Configuring SAML SSO Artifact Profile Resource Policy (NSM Procedure) on page 226
Defining a Basic Authentication, NTLM, or Kerberos Intermediation Resource Policy
(NSM Procedure)
Basic authentication, NT LAN Manager (NTLM), or Kerberos intermediation resource
policies enable you to control NTLM and Kerberos intermediation on the Secure Access
device. If a user accesses a Web resource that sends a basic authentication challenge,
the device intercepts the challenge, displays an intermediate sign-in page to collect the
credentials for the Web resource, and then rewrites the credentials along with the entire
challenge or response sequence.
With the Kerberos intermediation resource policy, backend Web applications protected
by Kerberos are accessible to end users. For example, a user logs in to the device using
Active Directory as the authentication server and the authentication protocol is Kerberos.
When the user browses a Kerberos-protected server, the user is single signed on to the
backend server and is not prompted for any credentials. A user logs in to the device using
an authentication protocol other than Kerberos and then browses a Kerberos-protected
server. Depending on the Kerberos intermediation resource policy settings and the
configured Kerberos authentication server, the user is either authenticated by the system
or is prompted to enter a username and password.
To define a basic authentication, NTLM, or Kerberos intermediation resource policy:
1.
In the navigation tree, select
Device Manager > Devices
.
2.
Click the
Device Tree
tab, and then double-click the Secure Access device for which
you want to configure a basic, NTLM, or Kerberos intermediation resource policy.
3.
Click the
Configuration
tab. Select
Users > Resource Policies > Basic Auth/NTLM
SSO
.
221
Copyright © 2010, Juniper Networks, Inc.
Chapter 14: Configuring Single Sign-On
Summary of Contents for NETWORK AND SECURITY MANAGER
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 12: ...Copyright 2010 Juniper Networks Inc xii Configuring Secure Access Devices Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii Configuring Secure Access Devices Guide...
Page 20: ...Copyright 2010 Juniper Networks Inc 2 Configuring Secure Access Devices Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 10 Configuring Secure Access Devices Guide...
Page 40: ...Copyright 2010 Juniper Networks Inc 22 Configuring Secure Access Devices Guide...
Page 46: ...Copyright 2010 Juniper Networks Inc 28 Configuring Secure Access Devices Guide...
Page 50: ...Copyright 2010 Juniper Networks Inc 32 Configuring Secure Access Devices Guide...
Page 52: ...Copyright 2010 Juniper Networks Inc 34 Configuring Secure Access Devices Guide...
Page 82: ...Copyright 2010 Juniper Networks Inc 64 Configuring Secure Access Devices Guide...
Page 110: ...Copyright 2010 Juniper Networks Inc 92 Configuring Secure Access Devices Guide...
Page 154: ...Copyright 2010 Juniper Networks Inc 136 Configuring Secure Access Devices Guide...
Page 224: ...Copyright 2010 Juniper Networks Inc 206 Configuring Secure Access Devices Guide...
Page 234: ...Copyright 2010 Juniper Networks Inc 216 Configuring Secure Access Devices Guide...
Page 288: ...Copyright 2010 Juniper Networks Inc 270 Configuring Secure Access Devices Guide...
Page 300: ...Copyright 2010 Juniper Networks Inc 282 Configuring Secure Access Devices Guide...
Page 310: ...Copyright 2010 Juniper Networks Inc 292 Configuring Secure Access Devices Guide...
Page 312: ...Copyright 2010 Juniper Networks Inc 294 Configuring Secure Access Devices Guide...
Page 320: ...Copyright 2010 Juniper Networks Inc 302 Configuring Secure Access Devices Guide...
Page 322: ...Copyright 2010 Juniper Networks Inc 304 Configuring Secure Access Devices Guide...
Page 337: ...PART 6 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 338: ...Copyright 2010 Juniper Networks Inc 320 Configuring Secure Access Devices Guide...
Page 340: ...Copyright 2010 Juniper Networks Inc 322 Configuring Secure Access Devices Guide...