mdrabble Posted September 22, 2015 Posted September 22, 2015 Currently using IdentD on both mac and windows and it works well. I'm in the middle of sorting out a Terminal Server for our thin clients and unfortunately, IdentD gets confused so I need to get my TS to use something like NTLM with Terminal Services compatibility. I could use GPO loopback and get the TS to use a different proxy port for NTLM authentication but I'm thinking why add an extra layer of complication! So my questions are - for those people with smoothwall boxes, What authentication methods do you use? How well does auto Negotiate Kerberos/NTLM with Terminal Services compatibility work across the whole network (approx. 400 workstations in total including thin client things) Should I ditch IdentD and use AutoNegotiate Kerberos/NTLM with Terminal Services compatible? Cheers Mark
karlr Posted September 24, 2015 Posted September 24, 2015 We currently use NTLM for Windows clients and IdentD for Macs. It would be nice to switch to IdentD across the board, but there are a few security implications to doing this. Not sure why ident would work incorrectly under terminal services? Presumably you are running an ident daemon as a service. In this case it should be able to correctly map the owner of the local/remote ports in question, unless there's something special about a terminal services session?
mdrabble Posted September 24, 2015 Author Posted September 24, 2015 After following advice from @Achandler I have moved my authentication over the Kerberos (Terminal Services Compatibility mode) Works great for Windows, Mac and my Terminal Servers.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now