This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to allow clients to authenticate on STAS over a IpSec VPN

Hi everyone, I really need some help. I've already tried some KBs but no luck.

I'm having some trouble configuring my branch office users to connect to my Active Directory Server on the head office site.

I have already set up IPSec VPN from Head Office (Sophos XG 115) to Branch Office (Sophos XG 105 without license).

I have already followed the KBs: https://docs.sophos.com/nsg/sophos-firewall/19.0/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Authentication/HowToArticles/AuthenticationAllowSTASOverVPN/index.html#introduction 

https://support.sophos.com/support/s/article/KB-000035839?language=en_US 

What is happening: 

By the time I login in the computer on the branch office (using a domain user), Sophos Firewall at Head Office gets the IP from Sophos Firewall Branch Office and not the IP from the workstation. After logging in, the browser pops up the login page from sophos firewall from Head Office. I can log through it normally, but the transparent authentication won't work.properly.

Sophos Firewall on the Head Office site: 192.168.1.1

Sophos Firewall on the Branch Office site: 192.168.5.1

Workstation on the Branch Office site: 192.168.5.20

Domain controller: 192.168.1.11

For the Head Office network users, it is everything ok with STAS. I`ve already set up the Servers, Services and STAS tab below like my Head Office Firewall. 

Head Office Sophos Firewall: 

Here it should be 192.168.5.20.

What can I do so Sophos Firewall gets the correct IP 192.168.5.20 from the workstation on Branch Office site?

Thank you guys.  



This thread was automatically locked due to age.
  • Hi 

    I did according to what you've said and I've got some progress!!! 

    Now, the STAS from HO is getting BO's Firewall IP Address for the first time!! Also, I can get the BO's workstation IP 192.168.5.20 in "live users"

    Additionally, the BO's Firewall is getting the workstation IP address in Current Activities:

    However, the workstation is not getting internet access. It is asking for login on HO's Sophos Firewall. Also, in HO's Firewall live users, the BO's user won't appear.

    In my VPN > WAN rule, in the HO's firewall, If I check the box bellow "match known users " I get no internet access in the workstation on BO, as shown in snapshot 2.

    Snapshot 1:

    Snapshot 2:

    In case I leave unchecked I get internet access normally. I need to use this option because I have different users groups on BO. So I need each one of the users get the correct firewall rule according to my web policies.

    What may I missing now? Is there a way to make it work properly using "match known users"?

    Thank you so much!!

    Best regards,