Is there any way round this? "In transparent mode, the proxy will strip NTLM authentication headers from HTTP requests". Is it the same with all Transparent proxys?
NTLM is problematic for many proxies, including Astaro's. In transparent mode, you can simply add the site to the transparent mode skiplist:
Web Security > HTTP > Advanced tab > Transparent Mode Skiplist
In standard or SSO modes, the site can be added to the browser as an exception.
In either case, a packet filter rule will also need to allow access to the site.