cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted

Multi Domain authenticatio

Jump to solution

DEar whome

i have question if i have 2 domain How would mcafee WG know which domain that they need to authen to

1. I have domain A and domain B but i dont know how mcafee select which domain that  mwg will choose when user authen to them , trying to use authentication realm to detect but it got blank value 

2. Should i use NTLM authen for multi domain or should i use another method. Cant separate by network

1 Solution

Accepted Solutions
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 4

Re: Multi Domain authenticatio

Jump to solution

Hi,

 

Hope you are doing well.

 

Yes you can use NTLM. Below is an recommendeded via of setting up NTLM Authentication when using multiple domains:-


Option here is having one setting, without using default domain value so client give the information in the authentication handshake which domain to use. MWG will use the proper domain then to authenticate.


I set up 2 AD servers one with domain lab.com and other with domain sathram.net as per screenshot attached.


In Windows domain membership you specify domain, so for one I have specified lob.com and for other I have specified sathram.net.


Now their an NTLM negotiation happens between client and MWG wherein in NTLM auth message client sends domain and username information


I have imported NTLM Authentication rule set from rule set library and have created authentication method NTLM in which in default domain name I have left it blank and not specified any domain name as per screenshot attached.


Here we have not specified domain name in NTLM settings and making sue of domain name which client sends in NTLM AUTH message and accordingly MWG will send to that DC server mapped with that domain in Windows domain membership.


I did testing with one user in sathram.net domain and once that user logged in via that domain, MWG only send Auth request to DC server of sathram.net by looking at domain name sent in NTLM AUTH message by client and similarly did testing with one user logged in via domain lab.com and MWG sent AUTH request from client for verification to DC server of lab.com domain only.

 

 

Was my reply helpful? If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!

 

Regards

Alok Sarda

View solution in original post

3 Replies
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 4

Re: Multi Domain authenticatio

Jump to solution

Hi,

 

Hope you are doing well.

 

Yes you can use NTLM. Below is an recommendeded via of setting up NTLM Authentication when using multiple domains:-


Option here is having one setting, without using default domain value so client give the information in the authentication handshake which domain to use. MWG will use the proper domain then to authenticate.


I set up 2 AD servers one with domain lab.com and other with domain sathram.net as per screenshot attached.


In Windows domain membership you specify domain, so for one I have specified lob.com and for other I have specified sathram.net.


Now their an NTLM negotiation happens between client and MWG wherein in NTLM auth message client sends domain and username information


I have imported NTLM Authentication rule set from rule set library and have created authentication method NTLM in which in default domain name I have left it blank and not specified any domain name as per screenshot attached.


Here we have not specified domain name in NTLM settings and making sue of domain name which client sends in NTLM AUTH message and accordingly MWG will send to that DC server mapped with that domain in Windows domain membership.


I did testing with one user in sathram.net domain and once that user logged in via that domain, MWG only send Auth request to DC server of sathram.net by looking at domain name sent in NTLM AUTH message by client and similarly did testing with one user logged in via domain lab.com and MWG sent AUTH request from client for verification to DC server of lab.com domain only.

 

 

Was my reply helpful? If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!

 

Regards

Alok Sarda

View solution in original post

Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 3 of 4

Re: Multi Domain authenticatio

Jump to solution

Hi,

 

Adding 2 more screenshot

 

Regards

Alok Sarda

Highlighted

Re: Multi Domain authenticatio

Jump to solution

many many thanks this is exactly what i am looking for

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community