Users report that they receive authentication popup when using Firefox, but when using Internet Explorer, no authentication popup is displayed and users can access the internet normally.
The proxy is deployed in transparent mode with a redirect-based authentication mode.
This happens because of how transparent proxy authentication takes place. The ProxySG is configured with a Virtual URL that resolves to one of its IP addresses. When a request reaches the proxy transparently, the proxy must redirect that request to itself to issue the authentication challenge. If configured per the documentation, the Virtual URL (located in the Management Console under Authentication > IWA > IWA General) is a single hostname, (such as http://ProxySG). By default, Internet Explorer will consider this URL as an internal intranet website and will try to automatically authenticate using NTLM credentials.
Firefox, however, does not have any such default configuration, so it will consider the ProxySG's Virtual URL as an external link. Because of this, it will not automatically provide the network logon name credentials automatically, so the popup appears to the user.
In order to resolve this issue, the Virtual URL can be added to the list of URLs permitted to respond to NTLM challenges. Steps on this are below: