Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Login with Captcha

I have just connected to an XG Firewall and as well as the user name and password and underneath is a captcha image with a box to type in response.

Haven't seen anything about that?



This thread was automatically locked due to age.
  • This should also be an option to turn on, best practice or not, for users or admins.  Every time I think about trying XG again, I'm just being given more reasons not to, and stick to UTM.  If captcha goes to UTM, I'm uninstalling it.  There are ways around captcha and while may be a 'best practice', it's certainly not the 'best way to do it' and old tech ways of making someone just feel secure.

    OPNSense 64-bit | Intel Xeon 4-core v3 1225 3.20Ghz
    16GB Memory | 500GB SSD HDD | ATT Fiber 1GB
    (Former Sophos UTM Veteran, Former XG Rookie)

  • If I understand your point well, like it was mentionned before, these are CLI commands related to captcha

    system captcha_authentication_VPN show
    system captcha_authentication_VPN enable
    system captcha_authentication_VPN disable

    They just don't work however.  Except for the "show" option.

    Regards

    Paul Jr

  • Two consecutive screenshot:

    So.  No it does not work.

    Paul Jr

  • Hi  

    Could you please raise a support case and PM me with your case number for further investigation?

    Thanks,


    Florentino
    Director, Global Community & Digital Support

    Are you a Sophos Partner? | Product Documentation@SophosSupport | Sign up for SMS Alerts
    If a post solves your question, please use the 'Verify Answer' button.
    The Award-winning Home of Sophos Support Videos! - Visit Sophos Techvids
  • Received an answer from support this morning.

    The Captcha added are for the security purpose. You would not be able to remove them as of now. They will be visible if the firewall or user portal is access from WAN.

    Well.  Clearly, the tech there haven't read this post.  None of our Firewall behaves the same, and none is accessed from WAN or User Portal.  And yet, one consistently shows Captcha.  The screen shot aint lying.

    Paul Jr

  • FormerMember
    +1 FormerMember in reply to Big_Buck

    Hi  

    When the firewall is accessed using its public IP(in your case Port2) address the Captcha will appear and there is no option to disable it as of now on the WAN zone. 

    Captcha authentication serves as an extra security defense against scripted automated login attempts Captcha has been added to the XG Firewall admin and user portals on the WAN and VPN zones.

    Thanks,

  • H_Patel said:

     

    Captcha authentication serves as an extra security defense against scripted automated login attempts Captcha has been added to the XG Firewall admin and user portals on the WAN and VPN zones.

     

    Ban IP after x unsuccessful attempts, allow admin access only from specified ACL (perhaps with the ability to use name and not only IP), adding two factor auth (OTP, FIDO, DUO, ecc.. ). These are the extra security defense against scripted automated login.

    The only achievement for capcha is annoy the hell out of me every time I try to connect. And beeing an MSP this happens a lot of times in a single day.

     

  • I'm testing the version 18, and the captcha is still present on both LAN and WAN. I think that Sophos whitelisted only the traffic coming from subnet directly attached to LAN zone and not all traffic incoming from LAN zone.

     

    For example: if your Sophos LAN PortA subnet is 192.168.10.0/24, all traffic incoming from that subnet entering PortA won't ask you for captcha. Instead if the request came from a different subnet routed correclty on Sophos LAN PortA will present you the captcha form.

     

  • I just upgraded to 18 as well and had the same issue, but after I set the "Management" IP it stopped happening. Almost like that was the identifier for what interface NOT to put the CAPTCHA on.

    - Nathan Kodak