Radius SSO for APX

Hi all,

just want to give some feedback about this new Feature in V17.5 MR6.

https://community.sophos.com/products/xg-firewall/b/xg-blog/posts/sfos-17-5-mr6-released

Radius SSO authentication between XG and APX

Wireless users can be authenticated using Radius SSO between XG and APX. Now supports framed IP addresses in client accounting messages.

 

 

Had a discussion with  So i wanted to move this in a proper format.

 

Just to be sure, this feature is running smoothly in my setup.

 

It is working like this KBA is telling us: 

https://community.sophos.com/kb/en-us/134148

 

Basically the new APX Firmware adds the Framed IP Address into the Accounting information after a Client is logging into a wireless network. 

https://tools.ietf.org/html/rfc2865

 

XG is NOT intercepting those packets or redirecting those packets.

So we are relying on the Radius Server to "simply" forward those Accounting information back to XG. 

As we are using the already existing SSO mechanism from SFOS.

 

In Server2016 NPS, you simply create a new Radius Server (as Radius Server Group) and forward those accounting information to XG. 

https://docs.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-crp-rrsg-configure

https://social.technet.microsoft.com/Forums/ie/en-US/ae9d4097-3fb5-4a75-8631-dbb86cb12077/windows-server-2012-nps-not-forwarding-accounting-messages?forum=winserverNAP

 

XG will pick up this Accounting information (send by NPS with a proper Shared Secret) and match the framed IP to the matching User name. 

 

  • This is going to be a complaint because after speaking to a Sophos Engineer i realised in my happiness i genuinely was ignoring the APX note.

    Prodman and Dev only did just do the fix for APX only and not the tens of thousands of already sold and currently still in support and sales life of the AP series.

    So if you have an AP and not an APX, you are still better supported by a third party AP and not a Sophos own brand AP for RADIUS Accounting.

    This, for me, is quite anger inducing.

    Emile