• Sophos XGS 136 HA LDAP

    Patrick81
    Patrick81
    Schönen guten Morgen zusammen, Vielleicht hat hier jemand eine Idee und kann mir weiter helfen. Seid ca. 14 Tagen habe ich das Problem bei einem Kunden, dass die Sophos das AD nicht mehr erreicht bekommt. Wenn ich von einem anderen Server z.B. mit der…
    • Answered
    • 2 months ago
    • Sophos Firewall
    • German Forum
  • If you are not registered in Active Directory, you cannot access the internet?

    duzcebelediye bilgiislem
    duzcebelediye bilgiislem
    If you are not registered in Active Directory, you cannot access the internet. How can I do it?
    • 2 months ago
    • Sophos Firewall
    • Discussions
  • Web Server Authentication Policy by other group memberships

    Marlon Bellmann
    Marlon Bellmann
    Hello, I am trying to use Authentication Policies for one of our Web Servers to restrict access to members of three specific Active Directory groups. When the user logs in, the authentication log shows a successfull login, but the site just reloads…
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Quarantined Messages / Authentication failure / DMARC

    Alfonso Galvez
    Alfonso Galvez
    Hi, I'm struggling with the quarantine email, since we received a few emails that were sent to quarantined due to "Authentication failure / DMARC". Im not undestanding at forst it shows: spf=softfail smtp.mailfrom=XXXXXXX@usanainc.com ; dkim=none; dmarc…
    • Answered
    • 3 months ago
    • Sophos Email
    • Discussions
  • Sophos AD/SSo authentication issue

    sreehari s
    sreehari s
    After changing the authentication mechanism to AD sso Kerberos authentication. The client machines are getting additional popup for the browser authentication, so that internet traffic will be allowed. We have tried by adding the hostname in internet…
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • STAS random disconnects live users - FW webfilter is blocking then

    Speedfish
    Speedfish
    Hello Sophos Community, first of all everything worked with STAS the last months without any problems.This week starting from monday on we are experiencing random disconnects on our STAS backend (it seems). It hits several live users randomly. They…
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • User assigns always to just one AD group

    Ingo Buyny
    Ingo Buyny
    Hello, I have a problem with a user who belongs to several groups in my Active Directory. Two of these groups are present in my XGS. However, the user on the XGS is only a member of one group, and for organizational reasons I don't want to use this…
    • Answered
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Sophos XG does not recognize user group returned by NPS RADIUS server

    Haris Alatovic
    Haris Alatovic
    Hello everyone, I have issue with Sophos XG firewall running SFOS 19.5.4 MR-4-Build718 configured for authentication via RADIUS server running on Windows Server (NPS service) with Azure MFA extension. We use it for MFA for VPN users. It works fine except…
    • Answered
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • SSL VPN users password need to expire automatically after specific days

    Kiran Jedhe
    Kiran Jedhe
    Hi, Is there any option for ssl vpn user password will expire after specific days. Note:don't suggest AD.
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • sophos xg125 vpn client with smartcard authentication

    Udo Wack
    Udo Wack
    Dear community, In our company, logging in to the domain will only be possible with a smart card and without entering a password in future. In our case, this is a Yubikey 5. Is there any way to integrate the SSL VPN clients via smartcard? Kind regards…
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • I am looking for assistance with IPSEC VPN authentication for On Prem Active Directory & Azure Entra

    hashtag
    hashtag
    I am looking for assistance with IPSEC VPN authentication for On Prem Active Directory & Azure Entra I have two use cases. Both involve the Sophos Connect Client and XG firewall v19.5 or later: 1. XG firewall appliance on premise with a MS Windows…
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Windows Homedrive - mounting fails due to delayed firewall authentication

    LHerzog
    LHerzog
    When users have homedrives in Active Directory they fail to mount as network drive when the firewall rule to the sharing server has user authentication required. Also the login of the users is taking minutes, not seconds. This is because the user is not…
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • OTP Issues with several users

    Quallensaft
    Quallensaft
    Hello, sice some days we have the problem that with some users (will be more and more) OTP auth is failing: -> oath_totp_validate() failed for tokenid xxxxxxxxxxxxxxxxxxxxxx with error The OTP is not valid - OTP was working fine all the time before issues…
    • Answered
    • 3 months ago
    • Sophos Firewall
    • Discussions
  • Maximum limit for authentication server is 20

    Hydro4711
    Hydro4711
    Hello, i reach out to all of you as we are in a really bad situation. We are hosting several customers with active directorys and we just recently started migrating from UTM to XGS. Today we learned, there is a maximum of 20 servers you are allowed…
    • Answered
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Changed Active Directory username and now user's external send emails are rejected

    SteveGross
    SteveGross
    As the Subject line says, I changed a user's last name in Active DIrectory and the new name does not appear in either Mailboxes or People in the Sophos Email Security. Do I have to manually enter the new name? In both places? Is there a way to automatically…
    • 4 months ago
    • Sophos Email
    • Discussions
  • Sophos Client Authentication Agent issue with MSI package and the certificate

    Nick KEY
    Nick KEY
    Hi , I have a issue with the Sophos Client Authentication Agent the "MSI" File. If I deploy the Agent with MSI File, it installed it and I can run it, but I am getting the error with Certificate (I think the ClientAuth_CA.scc) file cannot be find. …
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • CCA not working behind another XGS and RED

    Dennis Kirschner
    Dennis Kirschner
    Hello, We use the Client Authentication Agent (CCA) for authentication when accessing our network. We use the client at various external locations which are all connected via RED. At one location (behind a Sophos UTM) this works without any problems…
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • AD Domain join not possible

    Ben@Network
    Ben@Network
    Hi Community, I try to join a Sophos Firewall into our Windows domain but the domain join is not passible. I get this errors in /log/nasm.log: Jul 26 11:59:18.983130Z ha.c:30 is_ad_join_required [nasm] is_ad_join_required() AD join required due to…
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • user auth - AD or Local or Both?

    Simon Denham
    Simon Denham
    Hello, New bloke here. I read a lot of How To do a thing in XGS, but not why... What would be the intended purpose of a duplicated Administrator Local User and AD user? Is it redundancy in case the AD is unavailable? Should the default administrator…
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Complete Radius NPS Guide with EAP and certificate available?

    Cero01
    Cero01
    Hello everyone, is there a complete Guide available for setting up XGS and NPS with EAP and certificate authentication? We want to move on from a working EAP and MSChapv2 configuration because it is deprecated. i wonder, do i need to change…
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Changing Active Directory server when using SSL VPN authentication

    GunnAdmin
    GunnAdmin
    Hi, I've got a question about AD/LDAPS integration. Here's a quick rundown of the situation: -I have a client with an XGS116 (SFOS 19.5.2 MR-2-Build624). -Employees are currently using the Remote access SSL VPN to log into an RDS server with the Sophos…
    • Answered
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • User Authentication over S2S IPSec VPN

    CV_Sophos
    CV_Sophos
    We have currently have two locations, each with a XG330 v19.5.4 MR4 and an EPL fiber connection between them that has a S2S IPSec tunnel setup and a static route on both ends pointing to the other. Each FW is setup with the local DC for user authentication…
    • Answered
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Entra ID SSO

    twister5800
    twister5800
    Hi, Running SFOS 20.0.1-MR1, have setup Azure/Entra ID for SSO I can: - Use the test button under the Entra account, it shows grren. - I can connect and import groups into the firewall from Entra - I can sign into the firewall I cannot…
    • 4 months ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS Setting up LDAPS for authentication (Port 636) with Two DCs

    Rachel Salvadeo
    Rachel Salvadeo
    Hey all, I have a question that seems to not be addressed in any other related community forum I could find. I have two DCs, one of them being the Primary DC and the other being the Backup DC. Both DCs are replicating changes to each other. In the…
    • Answered
    • 5 months ago
    • Sophos Firewall
    • Discussions
  • sophos xg home to AD password/group synchronization

    Moeed Aziz
    Moeed Aziz
    Hi, I have Sophos home deployed in our network, with AD groups synced-in from AD server for user-based internet access. For a month or so now, when any users changes their domain user password, SSO (single sign on) does not work for them and they…
    • 5 months ago
    • Sophos Firewall
    • Discussions
<>