I have my Domain AD Server in Authentication>Servers menu
When new users created in AD, this users not being created in XG Firewall
I have successfully test connection in settings.
Do i have to use STAS for automatic synch between them ?
Hi Can carmack
The user will only reflect in the Sophos XG firewall once they authenticate with the firewall using available authentication method such as STAS or Captive Portal, for the first time they have to authenticate and then user will automatically create in the Sophos XG firewall, if you want them to sort in the same group as AD, please refer the given articles.
Regards,
Keyur
Community Support Engineer | Sophos Support
Sophos Support Videos | Knowledge Base | @SophosSupport | Sign up for SMS Alerts |
If a post solves your question use the 'This helped me' link
New AD users were absent in the firewall. Im not the one who integrated the AD system to firewall at installation.
I followed KBs and STAS method.
Duplicated users appeared. Some in open group, some as in AD.
User or groups in the firewall system is necessary for defining any policy or rule?
How about working with ips only
Hi Can carmack
For User and Group behavior, I have shared the documents, please refer to them that How Sophos XG manage groups and related users as compare to AD.
Users are required when you want some restrictions based on the user such as Content filtering, Authentication, Reports, and such other requirements.
IPS policy can be directly applied to the firewall rules as per your requirement. You do not require to have users to use IPS policy, It's up to your requirement and network configuration
For IPS
Regards,
Keyur
Community Support Engineer | Sophos Support
Sophos Support Videos | Knowledge Base | @SophosSupport | Sign up for SMS Alerts |
If a post solves your question use the 'This helped me' link
Thanks for reply.
After STAS integration duplicate users appeared in the firewall system.
Whatd be your advice for this users?
Hi Can carmack
Is there any other authentication mechanism you are using other than STAS?
Could you please share the screenshots?
Regards,
Keyur
Community Support Engineer | Sophos Support
Sophos Support Videos | Knowledge Base | @SophosSupport | Sign up for SMS Alerts |
If a post solves your question use the 'This helped me' link
Hi Keyur
No, just disabled STAS and uninstalled from server too.
Im confused about duplicate users after STAS try out.
In auth menu im using;
Servers > AD server
Services > Firewall auth methods; just local selected.
Clientless Users (Clientless Open Group) > 20+ defined
Thats all for auth.
What is the best method for users creation, manual or ad synch or?
Thanks bunch
Hi Can carmack
Please go through the KBAs that have been given as based on this reply, you have not set the AD integration correctly.
Duplicate users are generally created if you have a misconfiguration.
On the XG there is a setting for STAS. If you have more than 1 DC and you have assigned the DCs to each collector group, this will cause duplicate users.
Read the following articles completely:
https://community.sophos.com/kb/en-us/133531
https://community.sophos.com/kb/en-us/123156
https://community.sophos.com/kb/en-us/123154
https://community.sophos.com/kb/en-us/123023
https://community.sophos.com/kb/en-us/124848
https://community.sophos.com/kb/en-us/123029
Thanks!
KingChris
Community Support | Sophos Support
Sophos Support Videos | Knowledge Base | @SophosSupport | Sign up for SMS Alerts |
If a post solves your question use the 'This helped me' link
Thank you for detailed answer.
Is this tool solve the user-ip match issues
I can only see users who this agent installed and clientless users are properly reported.
Id like to create reports paired with users .
But now just ip numbers appear in the reports.
If i install this agent to users what happens?
Dhcp Statics List
No User name in Logs Screen
Hi Can carmack,
The Client Authentication Agent (CAA) is a lightweight agent for the sole purpose of authenticating users with the XG Firewall. This is the preferred option to authenticate users on the local network for the MAC based login restriction. Various flavors of OS are supported: Windows, MAC, Linux 32 & 64 bit.
With Client Authentication Agent users should be authenticated which means usernames should appear in reports.
Read this KB Article for detailed information : https://community.sophos.com/kb/en-us/133124
Thanks,
Is this tool enough for keeping user activity in logs and reports?
Rather than AD integration?
Unknown said:Do i have to use STAS for automatic synch between them ?
As long as you follow that guide provided it will - however STAS will not remove the user when you remove them from AD
Sophos XG 450 (SFOS 18.5.1 MR-1)
Sophos R.E.D 50 x 2
Always configuring new stuff.....
Removing user is somehow a rare case on AD setups.
Most security departments need to save the users for monitoring, compliance reasons.
So those users gets disabled but not deleted.
__________________________________________________________________________________________________________________