Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSO Transparent Authentication "How To"

Hi,

We are with difficulty for authentication client on SSO mode(Single Sign On) transparent authentication.

I found a "How to" in site Sophos Community (community.sophos.com/.../123159) but using client "Sophos Single Sign-On Client" installed on workstation. We need to authenticate our windows AD users whithout  installing any client, Sophos SSO seems the way to do that but im not been able to do that. Users from AD are autenticating in user portal succesfully but SSO is not working properly as we required.

In latest version it was necesary to insert firewall into AD. but in new version i can not see where to do that, and i do not know if it is necessary.

Thank you for help!



This thread was automatically locked due to age.
Parents
  • Don't forget all the problems that SSO still have if you have particular service running on all clients.
    For example, my SSO don't work at all because I have Arcserve UDP (backup software) installed on every machine and it use a standard domain users (named Backup).
    For this reason STAS identify all the surfing made by user Backup instead of the logged user... I have also tryed a Cyberoam KB (Sophos haven't yet copied it!!!) about CTAS and similar problem, that suggest to add the user Backup on the exclusion list.
    After this, the firewall stops reporting all the trafic assigned to the user Backup, but nor it reports all the trafic made by N/A and if I block the trafic made by unauthenticated users all the users can't surf anymore!!....

    So, for my experience, SSO is great, but need a lot of improvements.
Reply
  • Don't forget all the problems that SSO still have if you have particular service running on all clients.
    For example, my SSO don't work at all because I have Arcserve UDP (backup software) installed on every machine and it use a standard domain users (named Backup).
    For this reason STAS identify all the surfing made by user Backup instead of the logged user... I have also tryed a Cyberoam KB (Sophos haven't yet copied it!!!) about CTAS and similar problem, that suggest to add the user Backup on the exclusion list.
    After this, the firewall stops reporting all the trafic assigned to the user Backup, but nor it reports all the trafic made by N/A and if I block the trafic made by unauthenticated users all the users can't surf anymore!!....

    So, for my experience, SSO is great, but need a lot of improvements.
Children
No Data