New XG deployment running SFOS 18.0.4
I have my primary internal network 192.168.10.x
I have a production VLAN 192.168.50.x
I have a firewall rule that allows ALL traffic between these 2 private networks. No user authentication. No web filtering. Plain vanilla firewall rule.
From a computer on the primary network I open a web browser and browse to a web page on the production network. Example: http://192.168.50.14
Using Google Chrome or Firefox. Immediately I get redirected to this URL > sophosxg.mydomain.com:8091/ntlmauth.html
First question is why is the xg trying to apply ANY sort of authentication between internal networks? (Both networks are in the LAN zone)
Interestingly: If I open Microsoft Edge browser and go to 192.168.50.14 immediately the page loads as expected. If I jump back to Chrome or Firefox and try to browse to that same site, now it works. Maybe 20 minutes later I try again on Chrome or Firefox, and it fails again. Hop over to Edge, page loads fine.
I have an active support ticket with Sophos and have demonstrated this to 3 or 4 techs and after lengthy remote sessions they all agree on the same thing: This should not be happening.
Anyone else experiencing this? Any suggestions?
I am using Active Directory SSO using Kerberos and NTLM. But isn't this ONLY supposed to come into play when going to the Internet? Plus, as I mentioned, my firewall rule that allows traffic between internal LAN has the "Match known users" option unchecked.
This thread was automatically locked due to age.