Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Citrix Netscaler 2FA Not Working with Sophos XG Web Server Protection

As with our current Sophos XGS Firewall Rules and Policies configurations, the Citrix Netscaler 2FA authentication is working.  We started planning of using the Sophos XG Firewall Web Server Protection.  The license required were purchased and registered to the Sophos XG Firewall.  We started configuring our Sophos XG Firewall Web Server Protection and start adding all our web servers and Citrix Netscalerk.

The Citrix Netscaler was working but the 2FA Authentication never popup to ask for the 2FA codes.  The Citrix Netscaler authentication just went through with the users username and password without 2FA requests.  We don't feel right and return the configuration back to the way it was before.  Then the 2FA works again.

Is there anything in the Web Server Protection that requires to be disabled in order to have the 2FA request works?



This thread was automatically locked due to age.
Parents
  • correct is: there is no 2FA within sophos WAF until now.
    But this should not stop netScaler 2FA.

    Do you try to disable all WAF protections at Sophos?

    Check (or post) the WAF log while authenticating at the netscaler.

    do you use the NS-integrated 2FA or an external RADIUS with challenge/response?


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Reply
  • correct is: there is no 2FA within sophos WAF until now.
    But this should not stop netScaler 2FA.

    Do you try to disable all WAF protections at Sophos?

    Check (or post) the WAF log while authenticating at the netscaler.

    do you use the NS-integrated 2FA or an external RADIUS with challenge/response?


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Children
No Data