Help us enhance your Sophos Community experience. Share your thoughts in our Sophos Community survey.

Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AD Authentication configured but users not allowed to login

Hi to all Sophos Community,

I was wondering if you had any idea on this problem.

First time using Sophos firewalls, mostly working on them via Sophos Central Web Admin. 

So I enabled IPSec VPNs, it does work with local created users.

Company asked me to use Active Directory Authentication, I configured the AD server, test connection worked, imported users and groups, made AD first authentication method, checked queries.

Am I missing something here? I used Sophos guide and youtube videos, can't pass through this stage.

Thank you for your attention

This thread was automatically locked due to age.
  • Hello Enrico,

    After looking at your screenshot, i would first check if the Active Directory User or Group is allowed in the IPSec Client VPN Configuration.
    If the firewall cant Authenticate the user throu the Auth Server there will be the Error Message "wrong username/password".

    You are getting "not allowed". The Firewall can authenticate the User but the Service is denied.

  • Hello Enrico,

    After looking at your screenshot, i would first check if the Active Directory User or Group is allowed in the IPSec Client VPN Configuration.
    If the firewall cant Authenticate the user throu the Auth Server there will be the Error Message "wrong username/password".

    You are getting "not allowed". The Firewall can authenticate the User but the Service is denied.
