Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AD Authentication Server Configuration Problem

hello everyone

here iam still trying to configure all rules i need to apply on my work environment

i have read that i can setup my AD as authentication server to let users access the internet

but i couldn't make it work and i hoped to figure out the problem with you guys

so this is my configuration

Network IP : 10.10.10.0/24

Sophos GW : 10.10.10.1

DC : 10.10.10.2

my first step was add DC to Authentication Servers

 

then i configured the authentication method as the following

then i imported all of the OUs to Sophos

then i have created a firewall rule to allow access for example to HR OU users

finally i have logged in with a user from HR OU and another testing OU

and i have signed in Captive portal with there AD usernames too

but the problem is when i signed in with the HR username i couldn't access the internet

so what i have missed ?

thanx in advance for any help :)



This thread was automatically locked due to age.
Parents
  • Under Authentication > Groups could you confirm their Surfing Quota is not limited?

    Also, on the LAN>WAN firewall rule you created for the HR OU did you enable Masquerading and/or select a Web Policy?

    Karlos
    Community Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.
  • the surfing quota policy is "Unlimited Internet Access"

    and for the firewall LAN>WAN rule the Masquerading is enabled and there is no web policy or application policy

    i have tested to ping on 8.8.8.8 from HR user and i can ping it successfully but cant surf the internet

    is there any missing step should do on the AD ?

Reply
  • the surfing quota policy is "Unlimited Internet Access"

    and for the firewall LAN>WAN rule the Masquerading is enabled and there is no web policy or application policy

    i have tested to ping on 8.8.8.8 from HR user and i can ping it successfully but cant surf the internet

    is there any missing step should do on the AD ?

Children