Sussex-cancer-centre
Portfolio

Projects & Case Studies

A showcase of proxy authentication, network access and 407 remediation projects delivered for enterprises, public-sector organisations and technology teams across the UK and beyond.

Selected Engagements

Each project below addressed the HTTP 407 Proxy Authentication Required challenge in a distinct environment.

Global bank proxy authentication overhaul
Financial Services

Global Bank — Proxy Authentication Overhaul

We migrated 12 000 workstations from Basic proxy authentication to mutual TLS with Kerberos fallback across 40 branch offices. The project eliminated all recurring 407 errors caused by stale cached credentials and reduced help-desk tickets by 71 %.

  • Phased rollout over nine weeks with zero unplanned downtime
  • Automated credential provisioning via Group Policy
  • Comprehensive runbook for the in-house operations team
NTLM Kerberos Group Policy
Healthcare secure web gateway implementation
Healthcare

NHS Trust — Secure Web Gateway Deployment

A regional NHS trust needed a compliant Secure Web Gateway with strict proxy authentication for clinical and administrative networks. We designed a tiered authentication model separating clinician, service-account and vendor access — all of which previously collided and triggered mass 407 responses.

  • Integration with Active Directory and a custom RADIUS bridge
  • Audit logging aligned with DSPT requirements
  • Zero-trust access tiers with per-group Proxy-Authorization policies
Secure Web Gateway Active Directory Compliance

You may like

Project Delivery Timeline

How a typical proxy remediation engagement unfolds.

Week 1

Discovery & Traffic Analysis

We capture representative traffic, catalogue every Proxy-Authenticate challenge and map the client applications that are failing with HTTP 407.

Week 2–3

Architecture & Scheme Selection

Based on the inventory we recommend the authentication scheme or combination that balances security, compatibility and operational effort.

Week 4–6

Pilot & Validation

A representative subset of users and services is migrated first. We monitor for unexpected 407 or 403 responses and tune the configuration.

Week 7–9

Full Rollout & Handover

Remaining endpoints are migrated, monitoring dashboards go live and the operations team receives a complete knowledge-transfer package.

Skills & Technologies Applied

Every portfolio project draws on a focused set of proxy and network-access competencies. We stay within this domain so we can deliver deeper insight than a generalist consultancy.

🌐

Forward Proxy Engineering

Squid, NGINX, Apache Traffic Server, Zscaler and Blue Coat / Symantec ProxySG configuration and tuning.

🔑

Authentication Schemes

Basic, Digest, NTLMv2, Kerberos, SPNEGO, mutual TLS and OAuth 2.0 token-based proxy authentication.

📦

Automation & IaC

Ansible, Terraform and Puppet modules for consistent proxy configuration across thousands of endpoints.

📈

Observability

ELK dashboards and Prometheus metrics that surface 407 rates by application, user and proxy node in real time.

Network infrastructure and proxy server setup

Results Across All Projects

71 %
Average reduction in 407 help-desk tickets
0
Unplanned outages during rollout
9 weeks
Typical end-to-end engagement
100 %
Projects delivered with handover runbook

Ready to Eliminate 407 Errors in Your Organisation?

Let's scope a project that restores seamless, secure proxy access for every user and service.

Start a Conversation