Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG does not recognize user group returned by NPS RADIUS server

Hello everyone,

I have issue with Sophos XG firewall running SFOS 19.5.4 MR-4-Build718 configured for authentication via RADIUS server running on Windows Server (NPS service) with Azure MFA extension. We use it for MFA for VPN users. It works fine except recognition of user group membership returned in Filter-Id field by NPS server. I have checked with Wireshark that NPS service returns Filter-Id field containing correct user group. However, Sophos XG accept response from NPS server and user get authenticated but user group is not recognized and user falls into Open Group only. Note that I have configured Filter-Id as Group member attribute in Sophos XG definition for RADIUS server. In addition, have checked debug access_server.log on Sophos XG firewall and found following:



This thread was automatically locked due to age.
Parents
  • Thank you Alok! Meanwhile I have found a solution! Maybe the group membership with RADIUS does not work with the Filter-Id Attribute, but with with the Class Attribute my XG is able to put the users into my user group that I created! Would be nice if you could test this and maybe put it in your official docs.

  • Thanks Marcel for the update.

    Ideally, it should work with any attribute which is configured on Firewall and sent by Radius with appropriate value. 

    If same values are sent via Filter-ID or Class or any Other. I don't see a reason it should not work.

    As from firewall PoV, it will retrieve the response from defined attribute under "Group name attribute" on SFOS and try to map with existing locally available group info.

    -Alok

  • Cant explain this behavior. I know what you mean, when the GID is Filter-Id, it is Filter-Id. I dont know it only works with Class.

  • If it's possible we can arrange remote session to have a look at your setup with Fiter-ID and Class. 

    I have DM you.

Reply Children
No Data