<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intermittent auth with NTLM in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263747#M738</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem didn't come back anymore. What had happen was intermittent. We did a Test Query to LDAP from our domain and saw time stamp variance between WSA and AD. Found out later NTP server where WSA point is not responding so we reset the NTP box and things are better.&lt;BR /&gt;&lt;BR /&gt;Attempting to get TGT...&lt;BR /&gt;&lt;BR /&gt;Failure: Error while fetching Kerberos Tickets from server 'server1.gas.com.au' :&lt;BR /&gt;kinit: krb5_get_init_creds: Clock skew too great &lt;BR /&gt;&lt;BR /&gt;Failure: Error while fetching Kerberos Tickets from server 'server2.gas.com.au' :&lt;BR /&gt;kinit: krb5_get_init_creds: Clock skew too great &lt;BR /&gt;&lt;BR /&gt;Failure: Error while fetching Kerberos Tickets from server 'server3.gas.com.au' :&lt;BR /&gt;kinit: krb5_get_init_creds: Clock skew too great &lt;BR /&gt;&lt;BR /&gt;Checking local WSA time and server time difference...&lt;BR /&gt;&lt;BR /&gt;Warning: Clock skew between WSA 'Mon Oct 12 14:30:52 2009' and AD server 'Mon Oct 12 14:36:27 2009' is too great&lt;BR /&gt;&lt;BR /&gt;Warning: Clock skew between WSA 'Mon Oct 12 14:30:52 2009' and AD server 'Mon Oct 12 14:36:27 2009' is too great&lt;BR /&gt;&lt;BR /&gt;Warning: Clock skew between WSA 'Mon Oct 12 14:30:52 2009' and AD server 'Mon Oct 12 14:36:27 2009' is too great&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Oct 2009 15:04:49 GMT</pubDate>
    <dc:creator>rngai_ironport</dc:creator>
    <dc:date>2009-10-29T15:04:49Z</dc:date>
    <item>
      <title>Intermittent auth with NTLM</title>
      <link>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263741#M732</link>
      <description>&lt;P&gt;This problem is quite subjective as it may be desktop setting vary from another but never or less, I hope you could share some insight how to get to the bottom of this.&lt;BR /&gt;&lt;BR /&gt;There are few client intermittently get popup auth screen, which they should not because their PC join the domain and C360 is configure to use NTLM only. There 3 websites we sample and isolate which exhibit this problem. They are:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.saptechnical.com/" target="_blank"&gt;http://www.saptechnical.com/&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://myxcelsius.com/" target="_blank"&gt;http://myxcelsius.com/&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://www.forumtopics.com/" target="_blank"&gt;http://www.forumtopics.com/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;From access log, I could see the http request was made but all of sudden they get 407. Could it be http version IE use? What ver of http C360 recommend? 1.0 or 1.1? Here's a snapshot:&lt;BR /&gt;&lt;BR /&gt;SAPTechnical website&lt;BR /&gt;1255990207.043 268 10.9.131.58 TCP_REFRESH_HIT/200 1072 GET &lt;A href="http://www.saptechnical.com/images/sidebarbg.jpg" target="_blank"&gt;http://www.saptechnical.com/images/sidebarbg.jpg&lt;/A&gt; "GASCOM\smith@GAS-AD-DOMAIN" DIRECT/www.saptechnical.com image/jpeg OTHER-NONE-AD_AUTH-NONE-NONE-DefaultRouting &amp;lt;Comp&amp;gt; - "0" "0" "0" "0" "0" "0" "264" "264"&lt;BR /&gt;1255990207.043 265 10.9.131.58 TCP_REFRESH_HIT/200 1209 GET &lt;A href="http://www.saptechnical.com/images/bullet.gif" target="_blank"&gt;http://www.saptechnical.com/images/bullet.gif&lt;/A&gt; "GASCOM\smith@GAS-AD-DOMAIN" DIRECT/www.saptechnical.com image/gif OTHER-NONE-AD_AUTH-NONE-NONE-DefaultRouting &amp;lt;Comp&amp;gt; - "0" "0" "0" "0" "0" "0" "261" "261"&lt;BR /&gt;&lt;B&gt;&lt;SPAN style="color: red;"&gt;1255990207.055 0 10.9.131.58 TCP_DENIED/407 3333 GET &lt;A href="http://www.saptechnical.com/Tutorials/BI/Xcelsius/Index.1.jpg" target="_blank"&gt;http://www.saptechnical.com/Tutorials/BI/Xcelsius/Index.1.jpg&lt;/A&gt; - NONE/- - OTHER-NONE-AD_AUTH-NONE-NONE-NONE &amp;lt;-,-,-,-,-,-,-,-,-,-,-,-,-,-,-&amp;gt; - "0" "0" "0" "0" "0" "0" "0" "0"&lt;BR /&gt;1255990207.059 0 10.9.131.58 TCP_DENIED/407 3333 GET &lt;A href="http://www.saptechnical.com/Tutorials/BI/Xcelsius/Index.2.jpg" target="_blank"&gt;http://www.saptechnical.com/Tutorials/BI/Xcelsius/Index.2.jpg&lt;/A&gt; - NONE/- - OTHER-NONE-AD_AUTH-NONE-NONE-NONE &amp;lt;-,-,-,-,-,-,-,-,-,-,-,-,-,-,-&amp;gt; - "0" "0" "0" "0" "0" "0" "0" "0"&lt;BR /&gt;1255990207.078 0 10.9.131.58 TCP_DENIED/407 467 GET &lt;A href="http://www.saptechnical.com/Tutorials/BI/Xcelsius/Index.1.jpg" target="_blank"&gt;http://www.saptechnical.com/Tutorials/BI/Xcelsius/Index.1.jpg&lt;/A&gt; - NONE/- - OTHER-NONE-AD_AUTH-NONE-NONE-NONE &amp;lt;-,-,-,-,-,-,-,-,-,-,-,-,-,-,-&amp;gt; - "0" "0" "0" "0" "0" "0" "0" "0"&lt;/SPAN&gt;&lt;/B&gt;&lt;BR /&gt;1255990207.268 222 10.9.131.58 TCP_REFRESH_HIT/200 1115 GET &lt;A href="http://www.saptechnical.com/images/textbg.jpg" target="_blank"&gt;http://www.saptechnical.com/images/textbg.jpg&lt;/A&gt; "GASCOM\smith@GAS-AD-DOMAIN" DIRECT/www.saptechnical.com image/jpeg OTHER-NONE-AD_AUTH-NONE-NONE-DefaultRouting &amp;lt;Comp&amp;gt; - "0" "0" "0" "0" "0" "0" "215" "215"&lt;BR /&gt;1255990207.307 226 10.9.131.58 TCP_REFRESH_HIT/200 14139 GET &lt;A href="http://www.saptechnical.com/Tutorials/BI/Xcelsius/Index.1.jpg" target="_blank"&gt;http://www.saptechnical.com/Tutorials/BI/Xcelsius/Index.1.jpg&lt;/A&gt; "GASCOM\smith@GAS-AD-DOMAIN" DIRECT/www.saptechnical.com image/jpeg OTHER-NONE-AD_AUTH-NONE-NONE-DefaultRouting &amp;lt;Comp&amp;gt; - "6" "0" "0" "0" "0" "0" "216" "216"&lt;BR /&gt;&lt;BR /&gt;Forumtopics website&lt;BR /&gt;1255990242.668 197 10.9.131.58 TCP_REFRESH_HIT/200 770 GET &lt;A href="http://www.forumtopics.com/busobj/templates/bob/formIE.css" target="_blank"&gt;http://www.forumtopics.com/busobj/templates/bob/formIE.css&lt;/A&gt; "GASCOM\smith@GAS-AD-DOMAIN" DIRECT/www.forumtopics.com text/x-c OTHER-NONE-AD_AUTH-NONE-NONE-DefaultRouting &amp;lt;Blog&amp;gt; - "0" "0" "0" "0" "0" "0" "192" "192"&lt;BR /&gt;1255990243.888 1200 10.9.131.58 TCP_MISS/200 82960 GET &lt;A href="http://www.forumtopics.com/busobj/images/banners/xenon_top_banner_v2.swf" target="_blank"&gt;http://www.forumtopics.com/busobj/images/banners/xenon_top_banner_v2.swf&lt;/A&gt; "GASCOM\smith@GAS-AD-DOMAIN" DIRECT/www.forumtopics.com application/x-shockwave-flash MONITOR_CUSTOMCAT_1090519042-GeneralGroup-AD_AUTH-NONE-NONE-DefaultRouting &amp;lt;C_Whit&amp;gt; - "0" "0" "0" "0" "0" "0" "1006" "192"&lt;BR /&gt;&lt;B&gt;&lt;SPAN style="color: red;"&gt;1255990244.218 0 10.9.131.58 TCP_DENIED/407 3333 GET &lt;A href="http://www.forumtopics.com/busobj/templates/bob/images/nav_print.gif" target="_blank"&gt;http://www.forumtopics.com/busobj/templates/bob/images/nav_print.gif&lt;/A&gt; - NONE/- - OTHER-NONE-AD_AUTH-NONE-NONE-NONE &amp;lt;-,-,-,-,-,-,-,-,-,-,-,-,-,-,-&amp;gt; - "0" "0" "0" "0" "0" "0" "0" "0"&lt;BR /&gt;1255990244.219 0 10.9.131.58 TCP_DENIED/407 3333 GET &lt;A href="http://www.forumtopics.com/busobj/templates/bob/images/nav_next.gif" target="_blank"&gt;http://www.forumtopics.com/busobj/templates/bob/images/nav_next.gif&lt;/A&gt; - NONE/- - OTHER-NONE-AD_AUTH-NONE-NONE-NONE &amp;lt;-,-,-,-,-,-,-,-,-,-,-,-,-,-,-&amp;gt; - "0" "0" "0" "0" "0" "0" "0" "0"&lt;BR /&gt;1255990244.231 0 10.9.131.58 TCP_DENIED/407 467 GET &lt;A href="http://www.forumtopics.com/busobj/images/smiles/banghead.gif" target="_blank"&gt;http://www.forumtopics.com/busobj/images/smiles/banghead.gif&lt;/A&gt; - NONE/- - OTHER-NONE-AD_AUTH-NONE-NONE-NONE &amp;lt;-,-,-,-,-,-,-,-,-,-,-,-,-,-,-&amp;gt; - "0" "0" "0" "0" "0" "0" "0" "0"&lt;/SPAN&gt;&lt;/B&gt;&lt;BR /&gt;1255990244.427 197 10.9.131.58 TCP_REFRESH_HIT/200 1622 GET &lt;A href="http://www.forumtopics.com/busobj/images/ranks/bobrank_06.gif" target="_blank"&gt;http://www.forumtopics.com/busobj/images/ranks/bobrank_06.gif&lt;/A&gt; "GASCOM\smith@GAS-AD-DOMAIN" DIRECT/www.forumtopics.com image/gif OTHER-NONE-AD_AUTH-NONE-NONE-DefaultRouting &amp;lt;Blog&amp;gt; - "0" "0" "0" "0" "0" "0" "191" "191"&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2009 09:11:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263741#M732</guid>
      <dc:creator>rngai_ironport</dc:creator>
      <dc:date>2009-10-20T09:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent auth with NTLM</title>
      <link>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263742#M733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The sneaky browser tries to get through the proxy without providing authentication first.  When the ironport replies with the request for authentication, the browser responds with the domain/user/password and the ironport checks that against your authentication source then delivers the content if the domain/user/password checks out.&lt;BR /&gt;&lt;BR /&gt;I routinely see a Request / Deny / Request with auth / Allow in my logs.&lt;BR /&gt;&lt;BR /&gt;If you use Wireshark on your pc or use it to look at a traffic capture from the ironport, you can see the 'authentication required' packet returned from the ironport.&lt;BR /&gt;&lt;BR /&gt;If you are getting the popup box, you may want to look at the authlogs on the ironport and it can tell you why are failing primary authentication.  IE &lt;PRE __jive_macro_name="code" class="jive_text_macro jive_macro_code" ___default_attr="plain"&gt;20/Oct/2009:14:22:54 -0500 INFO : PROX_AUTH : - : NTLM CRAP authentication for user [somedomain]\[someuser] returned NT_STATUS_ACCOUNT_LOCKED_OUT (PAM: &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt;&lt;/PRE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Oct 2009 04:46:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263742#M733</guid>
      <dc:creator>RBC____CS</dc:creator>
      <dc:date>2009-10-21T04:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent auth with NTLM</title>
      <link>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263743#M734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nothing found in authlogs, for 10 different sets of logs within that timeframe. Couldn't find the userid in that authlogs. &lt;BR /&gt;&lt;BR /&gt;Any more hint?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Oct 2009 08:16:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263743#M734</guid>
      <dc:creator>rngai_ironport</dc:creator>
      <dc:date>2009-10-21T08:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent auth with NTLM</title>
      <link>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263744#M735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm getting the exact same thing with my users - both IE and Firefox. It seems to happen on websites that use AJAX (hence alot of concurrent adhoc requests ?).&lt;BR /&gt;&lt;BR /&gt;I'm seeing things like&lt;BR /&gt;&lt;BR /&gt;23/Oct/2009:14:36:59 +1100 INFO : PROX_AUTH : - : NTLM CRAP authentication for u&lt;BR /&gt;ser [OFFICE]\[MyUser] returned NT_STATUS_NO_LOGON_SERVERS (PAM: 12)&lt;BR /&gt;23/Oct/2009:14:36:59 +1100 CRITICAL : PROX_AUTH : - : NTLMSSP BH: NT_STATUS_NO_L&lt;BR /&gt;OGON_SERVERS&lt;BR /&gt;&lt;BR /&gt;Both domain controllers are alive and well though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 11:47:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263744#M735</guid>
      <dc:creator>serialmonkey</dc:creator>
      <dc:date>2009-10-23T11:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent auth with NTLM</title>
      <link>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263745#M736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;serialmonkey-&lt;BR /&gt;&lt;BR /&gt;It is odd that you bring that up.&lt;BR /&gt;&lt;BR /&gt;I am getting similar messages on all 4 of my production ironports.  I have a ticket open with support escalated to the application engineers.  One of my ironports was so bad I had to take it out of service, yet the AD servers they auth against continue to hum along.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Oct 2009 02:08:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263745#M736</guid>
      <dc:creator>RBC____CS</dc:creator>
      <dc:date>2009-10-25T02:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent auth with NTLM</title>
      <link>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263746#M737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I might go ahead and raise a support ticket as well. Weight in numbers &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Oct 2009 09:52:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263746#M737</guid>
      <dc:creator>serialmonkey</dc:creator>
      <dc:date>2009-10-26T09:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent auth with NTLM</title>
      <link>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263747#M738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem didn't come back anymore. What had happen was intermittent. We did a Test Query to LDAP from our domain and saw time stamp variance between WSA and AD. Found out later NTP server where WSA point is not responding so we reset the NTP box and things are better.&lt;BR /&gt;&lt;BR /&gt;Attempting to get TGT...&lt;BR /&gt;&lt;BR /&gt;Failure: Error while fetching Kerberos Tickets from server 'server1.gas.com.au' :&lt;BR /&gt;kinit: krb5_get_init_creds: Clock skew too great &lt;BR /&gt;&lt;BR /&gt;Failure: Error while fetching Kerberos Tickets from server 'server2.gas.com.au' :&lt;BR /&gt;kinit: krb5_get_init_creds: Clock skew too great &lt;BR /&gt;&lt;BR /&gt;Failure: Error while fetching Kerberos Tickets from server 'server3.gas.com.au' :&lt;BR /&gt;kinit: krb5_get_init_creds: Clock skew too great &lt;BR /&gt;&lt;BR /&gt;Checking local WSA time and server time difference...&lt;BR /&gt;&lt;BR /&gt;Warning: Clock skew between WSA 'Mon Oct 12 14:30:52 2009' and AD server 'Mon Oct 12 14:36:27 2009' is too great&lt;BR /&gt;&lt;BR /&gt;Warning: Clock skew between WSA 'Mon Oct 12 14:30:52 2009' and AD server 'Mon Oct 12 14:36:27 2009' is too great&lt;BR /&gt;&lt;BR /&gt;Warning: Clock skew between WSA 'Mon Oct 12 14:30:52 2009' and AD server 'Mon Oct 12 14:36:27 2009' is too great&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Oct 2009 15:04:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/intermittent-auth-with-ntlm/m-p/1263747#M738</guid>
      <dc:creator>rngai_ironport</dc:creator>
      <dc:date>2009-10-29T15:04:49Z</dc:date>
    </item>
  </channel>
</rss>

