Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSO Transparent Authentication "How To"

Hi,

We are with difficulty for authentication client on SSO mode(Single Sign On) transparent authentication.

I found a "How to" in site Sophos Community (community.sophos.com/.../123159) but using client "Sophos Single Sign-On Client" installed on workstation. We need to authenticate our windows AD users whithout  installing any client, Sophos SSO seems the way to do that but im not been able to do that. Users from AD are autenticating in user portal succesfully but SSO is not working properly as we required.

In latest version it was necesary to insert firewall into AD. but in new version i can not see where to do that, and i do not know if it is necessary.

Thank you for help!



This thread was automatically locked due to age.
  • I reverted back to utm 9.3 since that works properly.
  • That folder is completely empty. Even after redownloading ISO and reinstalling.
  • I had the same issue on XG reinstall (after beta).
    After 6 hours, XG downloaded only 2 packages (Atp and Firmware AP). So I decided to reboot, and after 2 hours, all packages were downloaded.

    Luk
  • Well there are no packages to download, firmware updates state nothing new, system has been running since my first post and those files are still missing (SSH'd into system again this evening). Why would Sophos not have those files in ISO to begin with or at least available on the website as a manual download? IT seems to be an unfinished product that been released. but ranting aside, I am still waiting for away to actually get the XG firewall working.
  • Don't forget all the problems that SSO still have if you have particular service running on all clients.
    For example, my SSO don't work at all because I have Arcserve UDP (backup software) installed on every machine and it use a standard domain users (named Backup).
    For this reason STAS identify all the surfing made by user Backup instead of the logged user... I have also tryed a Cyberoam KB (Sophos haven't yet copied it!!!) about CTAS and similar problem, that suggest to add the user Backup on the exclusion list.
    After this, the firewall stops reporting all the trafic assigned to the user Backup, but nor it reports all the trafic made by N/A and if I block the trafic made by unauthenticated users all the users can't surf anymore!!....

    So, for my experience, SSO is great, but need a lot of improvements.
  • Hey Kranthi,

    I've followed these steps exactly.  everything appears to have installed and started up correctly, no errors.  but when, I look at my reports I still don't see usernames attached to the web activity.  right now, I am the only "user" who is connected to the XG unit for set up purposes. 

    I am browsing web with no errors and I'm not seeing the captive portal at all. but again, not seeing username in the reports/logs.

    I have run all of the tests in the STAS against my workstation and all checks out fine with no errors.

    any other config changes or troubleshooting ideas would be appreciated.

  • Zane -- make sure the XG can reach the STAS service on your domain controllers -- if you have the local Windows Firewall enabled you'll need to add a rule to allow inbound UDP 6677 to the DC for the XG to be able to poll the STAS service.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Sophos Platinum Partner

    --------------------------------------

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • Hi Kranthi Yadlapudi,

    I have an issue installing the STAS Suite on Windows Server 2008. When installing, it fails saying “Could not install STAS Service”. Re-installing the suite does not cause the error to pop up again, but when looking under windows services, the service is still not there.

    Why does the service not install? I am logged in as an administrator.

    Kind Regards,

    Werner