Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Sophos XG does not recognize user group returned by NPS RADIUS server

Hello everyone,

I have issue with Sophos XG firewall running SFOS 19.5.4 MR-4-Build718 configured for authentication via RADIUS server running on Windows Server (NPS service) with Azure MFA extension. We use it for MFA for VPN users. It works fine except recognition of user group membership returned in Filter-Id field by NPS server. I have checked with Wireshark that NPS service returns Filter-Id field containing correct user group. However, Sophos XG accept response from NPS server and user get authenticated but user group is not recognized and user falls into Open Group only. Note that I have configured Filter-Id as Group member attribute in Sophos XG definition for RADIUS server. In addition, have checked debug access_server.log on Sophos XG firewall and found following:



Added TAGs
[edited by: Erick Jan at 12:38 PM (GMT -7) on 26 Aug 2024]
Parents Reply Children
  • My group "WLANVPN" that I use for RADIUS is created on the firewall and the RADIUS and the "Filter-Id" Attribute which I use for the group name attribute is set to "WLANVPN" too on the RADIUS server. The group is sorted over all groups in the sophos group order menu. The users are the same, so the user "marcel" on sophos firewall was authentificated successfully with RADIUS. So the auth works, but the group membership of "WLANVPN" is not transferred. In my shell access log I can see the same behavior like Haris.

       I have not problems with authenticating users with RADIUS. But with group assignment.