This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

After updating to 9.501-5 SSO for HTTP authentication failed and domain join not working.

UTM 9.501-5

Windows server 2012 domain controller.

I installed the 9.5 update on June 2, did not see any issues with this for the client, updated to 9.501-5 on June 12 midnight, and Internet access is failing on multiple sites.

Can get to Google.ca

Cannot get to canada411.com - Too many http redirects message.

Turned off web filtering and the websites were available - but the client requires filtering.

Re-enabled and turned off AD SSO authentication and websites are available again with correct content being blocked.

Attempted to remove from and rejoin domain, but domain join failed.

 

Currently, I have the client functioning, but, I need to rejoin AD and resume SSO authentication.

 



This thread was automatically locked due to age.
Parents
  • Since I'm not seeing anything about AD synchronization and VPN authentication issues in this thread, I'm posting additional issues (which I'm sure are related to the same thing).

    All of my Sophos UTMs (7) are failing to sync with AD after upgrading (9.414 and 9.501 - both versions of firmware).  Re-joining to the domain does not solve this problem.  Since I have a web filtering exception that bypasses authentication, my web users can access the Internet, but this still needs to be resolved. BUT, my VPN users are being impacted.  If there isn't a local cache of users from a prior sync (before the upgrade), then the Sophos is unable to authenticate users connecting via VPN.  I'm also getting alerts about every 12 hours that the UTMs are unable to sync to AD.  I've already tried re-joining to the domain, but that didn't work. 

    I'm not sure if this is the root cause of the web filtering authentication issue or if this is separate, but the issue seems to be with AD authentication in general, not just with web filtering.

    How can Sophos release 2 updates without testing this and why is it taking so long to release a fix?  This is insane!

Reply
  • Since I'm not seeing anything about AD synchronization and VPN authentication issues in this thread, I'm posting additional issues (which I'm sure are related to the same thing).

    All of my Sophos UTMs (7) are failing to sync with AD after upgrading (9.414 and 9.501 - both versions of firmware).  Re-joining to the domain does not solve this problem.  Since I have a web filtering exception that bypasses authentication, my web users can access the Internet, but this still needs to be resolved. BUT, my VPN users are being impacted.  If there isn't a local cache of users from a prior sync (before the upgrade), then the Sophos is unable to authenticate users connecting via VPN.  I'm also getting alerts about every 12 hours that the UTMs are unable to sync to AD.  I've already tried re-joining to the domain, but that didn't work. 

    I'm not sure if this is the root cause of the web filtering authentication issue or if this is separate, but the issue seems to be with AD authentication in general, not just with web filtering.

    How can Sophos release 2 updates without testing this and why is it taking so long to release a fix?  This is insane!

Children
No Data