Hello,
I'm posting a question because I'm having trouble setting up an administrator account generated by the AD for firewall access.
My customer wants two of the AD users to be able to log into the firewall administration portal.
I have tried several procedures without success. The users in question can log in via SSL VPN with the same password without any problems, but not to the administration console.
Here are the screenshots of the different configurations:
AD Server :
Authentication method :
AD user for test :
Administration access :
Here is the logs :
I can connect to SSL VPN with the same credentials :
My Firewall is a Sophos XGS136 and he is under the SFOS 18.5.1 MR-1-Build326 firmware.
I'm tryring to connect from the WAN zone, is it possible that is the problem ?
Did I forget a parameter?
Hello RaphaelleB,
Thank you for reaching out to the community, the current firmware SFOS 18.5.1 MR-1-Build326 was declared 31-MAR-2022.
Try updating to at least SF-OS 18.5 MR2 or higher the latest is SF-OS 18.5 MR3 and then check the results if you are facing the same issue...?
Retirement calendar for Sophos: https://support.sophos.com/support/s/article/KB-000035279?language=en_US
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Hello,
Thank you for your reply, i updated the firmware of my customer to the latest version :
But it didn't work :
Regards,
Raphaelle
RaphaelleB it still says because of the "wrong credentials"
This is the default admin user [type - Firewall Administrator] OR you created a user who is trying to authenticate on web for internet access ?
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Hello,
This is the same user from the local AD.
I'm trying to connect to the admin portal from the WAN zone.
The user can connect to VPN with the same credentials.
Regards,
Raphaelle
Hey RaphaelleB,
Just go to authentication > user > click on that user > change the user type from user to administrator
Then try again !!
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Hello,
I already changed the user type.
But i resolved my issue.
I read again this post : https://community.sophos.com/sophos-xg-firewall/f/discussions/10879/add-domain-user-account-as-administrator
And i realise that i didn't add ad server under Administrator Authentication Methods.
I added the AD server and it's works !
Thank you for your help !!!
Regards,
Raphaelle