Het 'documentation' (http://tinyurl.com/pgt25sx) about implementing
Kerberos in NAM states the following:

> 6.(Conditional) If you have users who are outside the firewall, they
> cannot use Kerberos. SPNEGO defaults first to NTLM, then to HTTPS basic
> authentication. Access Manager does not support NTLM, so the NTLM prompt
> for username and password fails. The user is then prompted for a
> username and password for HTTPS basic authentication, which succeeds if
> the credentials are valid.

Why is isn't it working when users are outside the firewall? When users
log-on to a member-server they have a Kerberos ticket right? Regardless
of the network.

Could someone explain this?

