Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Sophos XG does not recognize user group returned by NPS RADIUS server

Hello everyone,

I have issue with Sophos XG firewall running SFOS 19.5.4 MR-4-Build718 configured for authentication via RADIUS server running on Windows Server (NPS service) with Azure MFA extension. We use it for MFA for VPN users. It works fine except recognition of user group membership returned in Filter-Id field by NPS server. I have checked with Wireshark that NPS service returns Filter-Id field containing correct user group. However, Sophos XG accept response from NPS server and user get authenticated but user group is not recognized and user falls into Open Group only. Note that I have configured Filter-Id as Group member attribute in Sophos XG definition for RADIUS server. In addition, have checked debug access_server.log on Sophos XG firewall and found following:



Added TAGs
[edited by: Erick Jan at 12:38 PM (GMT -7) on 26 Aug 2024]
Parents
  • Thank you Alok! Meanwhile I have found a solution! Maybe the group membership with RADIUS does not work with the Filter-Id Attribute, but with with the Class Attribute my XG is able to put the users into my user group that I created! Would be nice if you could test this and maybe put it in your official docs.

  • Thanks Marcel for the update.

    Ideally, it should work with any attribute which is configured on Firewall and sent by Radius with appropriate value. 

    If same values are sent via Filter-ID or Class or any Other. I don't see a reason it should not work.

    As from firewall PoV, it will retrieve the response from defined attribute under "Group name attribute" on SFOS and try to map with existing locally available group info.

    -Alok

Reply
  • Thanks Marcel for the update.

    Ideally, it should work with any attribute which is configured on Firewall and sent by Radius with appropriate value. 

    If same values are sent via Filter-ID or Class or any Other. I don't see a reason it should not work.

    As from firewall PoV, it will retrieve the response from defined attribute under "Group name attribute" on SFOS and try to map with existing locally available group info.

    -Alok

Children