Hello,
since monday we have been having problems with the authentication service of our XGS4500 running on SFOS 21.0.0 GA-Build169.
When the authentication service stops working, no more entries are added to the authentication log, users can't connect to our VPN and we can only sign in to the firewall using Sophos Central. After restarting the service everything starts working again.
We are using our domain controllers for authentication.
How do I find out what exactly is causing this problem?
Hello,
Thank you for reaching to the Sophos Community!
could you check if there are any coredump generated from advance shell?
# ls -lah /var/cores/
If this is happening too frequently, we suggest raising the support case to investigate it further.
Mayur Makvana
Technical Account Manager | Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
This is the output of ls -lah /var/cores/:
drwxrwxrwt 2 root root 4.0K Feb 5 13:50 .
drwxr-xr-x 47 root root 4.0K Feb 5 14:18 ..
-rw------- 1 root root 132.0K Feb 5 12:40 2452ad89-b22d-4e8c-0e32ea96-b5a38505.dmp
-rw------- 1 root root 140.0K Feb 4 11:00 3156959c-0387-490d-fc318ab7-f4613e51.dmp
-rw------- 1 root root 132.3K Feb 4 14:39 8eb803d0-df55-4436-7dba7fbd-376b981b.dmp
-rw------- 1 root root 132.3K Feb 4 14:40 aaf99057-f572-479a-b6a619a7-f91c2a46.dmp
-rw------- 1 root root 132.0K Feb 4 13:54 c4f8b6d1-3100-4a36-6e8277aa-9c1c5d77.dmp
-rw------- 1 root root 16.0M Feb 5 13:50 core.access_server
-rw------- 1 root root 184.5M Feb 3 15:02 core.sasi
-rw------- 1 root root 4.4M Jul 14 2024 core.sslvpn
-rw------- 1 root root 124.0K Feb 4 10:10 e322f98d-681a-471e-fd8d58b8-1b25af76.dmp
-rw------- 1 root root 136.0K Feb 4 11:56 e4824439-0c73-4dc7-95387a86-5a2b3859.dmp
-rw------- 1 root root 140.0K Feb 5 13:48 e6485b0f-cd2f-4e4f-9c7e9098-de8af47f.dmp
-rw------- 1 root root 132.0K Feb 4 21:01 eac232e0-d964-4f4a-05fd74a5-3894f2e4.dmp
Hello,
The logs file suggest that there is coredump generated for the access_server. Please raise the support case and share the device access ID on case to investigate it further.
Mayur Makvana
Technical Account Manager | Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Hello,
Please share the ticket ID to track it.
Mayur Makvana
Technical Account Manager | Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Just for info I have also got the same issue on a XGS2100 running the exact same build. Ive rebooted my firewall and got the AD servers to be able to test connection correctly again but i still have all the users who cant VPN on or log in to the VPN portal. Also none of the admins can use their accounts to log into the firewall.
edit: everyone is working again now after a reboot of the firewall.
Hello PeteH ,
Could you perform the steps added in below KBA?
https://support.sophos.com/support/s/article/KBA-000009932?language=en_US
Even after performing above step if you encounter an issue. Check below command output and see if the coredump is generated for the recent date from advanced shell:
#ls -lah /var/cores/
If yes, kindly raise the support ticket to investigate it further.
Mayur Makvana
Technical Account Manager | Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
hi Mayur,
Not showing any issues with bruteforce attacks.
If we have another issue with VPN login etc not working i will check for coredump. Cheers