This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

After updating to 9.501-5 SSO for HTTP authentication failed and domain join not working.

UTM 9.501-5

Windows server 2012 domain controller.

I installed the 9.5 update on June 2, did not see any issues with this for the client, updated to 9.501-5 on June 12 midnight, and Internet access is failing on multiple sites.

Can get to Google.ca

Cannot get to canada411.com - Too many http redirects message.

Turned off web filtering and the websites were available - but the client requires filtering.

Re-enabled and turned off AD SSO authentication and websites are available again with correct content being blocked.

Attempted to remove from and rejoin domain, but domain join failed.

 

Currently, I have the client functioning, but, I need to rejoin AD and resume SSO authentication.

 



This thread was automatically locked due to age.
Parents
  • So I installed Firefox - it pops up a dialogue box and I enter my AD credentials and everything works.  Even in IE and Chrome.  Web Filter logs show my credentials correctly and I am being filtered correctly.

    Last night I ran up a VM and reverted to 9.413-4.1.  That was borked too - popping up authentication boxes every that wouldn't accept any credentials..

    So frankly I don't know what is going on.  So little sleep and so much stress from users and management (understandably) that I can't think my way out of a paper bag!

    I think I am just going to try rolling the Sophos Agent out - it works fine on the macs so I will see if it works on PCs..

    Sophos still not responding to emails.

  • Last post on this for me for now..

    Sophos Agent is pretty useless in a place with loads of PCs and users as the MSI installs to the user's appdata\local.  Can't be done quickly without thought and due process.

    So we have reverted back to browser based authentication (and the issues that has) so at least our users can actually access the web.  We had the embarrassment of having to take classes to another local school just so they could take an online test.  

    Absolutely fed up.

  • Don't worry! As you use "The Ultimate Security Package" which is "simpler, faster, better" you have just to wait two to three weeks more to get an emergency hotfix provided over Up2Date. Show stopper bug, and you have to wait four or five weeks to be fixed. Ridiciolous Sophos, and not the first time.

    As I do, you should never use the latest firmware on any productive system. Except there is really a massive security bug which makes UTMs to prefered targets. Let others be the idiots.

    Maybe this patch politics is subtile push for XG? Because of the old old architecture of UTM the bug was overseen and can only be fixed in weeeeeks. Our company will not extend premium support, simpy not worth the money. Nothing premium and shitty support and never helped on any problem.

  • Hi Thorsten,

    some comments, I would like to share about what you said, Im pretty much feeling the same:

     

    Thorsten Langer said:
    Ridiciolous Sophos, and not the first time.

    Yes, I absolutely with this, we are facing this bad QS and in general often bad support quality for about 3 Years now. I mean, sometimes it´s ok/good, but the most time, it´s really astonishing, how bad this support is.

     

    Thorsten Langer said:
    Our company will not extend premium support, simpy not worth the money. Nothing premium and shitty support and never helped on any problem.

    I´m also tending to not sell "premium support" any more, simply because it is not that, what its labeled as. As we are able to work with our distributor, we prefer this, they can also create tickets with higher priorisation.

     

    Probably you and the most of the members here won´t know it, this week I heard, that sophos officially anounced their politics/philosopy to their products, especially for UTM (and this is no Joke), Attention please, the sentence is analogous to what they said:

    In Deutsch:

    „Sophos Firmenpolitik zielt darauf ab möglichst mit vielen neuen Features auf den Markt zu drängen. Dabei ist die tatsächliche Funktion nebensächlich.“

     

    English:

    "Sophos´s philosophy is to become market leader in providing new features in their software, but that they really work is minor."

     

    Ok, now we now, it´s not a bug, it´s a feature, it´s their politics....

     

    BR

    Sebastian

  • Sebastian, wo hast Du daß gesehen/gehört?  Muß sagen - das stört mich.

    My experience is that there has been a real improvement in Support over the last year and that it's finally at least as good as what we were getting from Astaro. 

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

    BAlfson said:
    Muß sagen - das stört mich.

    the same for me, can´t really believe this. But from the Real live perspective, If somebody would ask me, if I can agree with that statement, I would says yes. Just a short sum up of the last view major issues: See all the bugs in 1.) Sandstorm, 2.) scanning within compressed mail attachements, announced for 9.3, was not working (our customer found out), 3.) STAS--> Sophos has really no idea, how it works. It´s full of bugs without and not working properly in HA-mode, there´s even no concept for snycing the stas data between the nodes, it is not part of the sync. Means firewall does a failover and user based firewall rules are not working any more. 4.) Whats with all the FAILED updates with major impact? If we would sum up all of them, I think the list will be long 5.) I have also numerous other tickets, where it becomes clear, that in some cases, there is really bad documentation and even knowledge from sophos emloyees about a feature or functionality.

     

    Back to topic:

    The statement that I mentioned came from our distributor, when I talked to them last week regarding fixing the AD/SSO problem. Today I asked for more details about that statement. The contact at our distributor told me, that he got in touch with this statement two times. One time he heard this from a colleague of him, who was informed about this on one of the roadshows in 2017. The next time, he heard this himself while speaking to a sales territory manager. It was clearly said, that this is officical and thus can be communicated to partners (like us). But he wants to ask for clarification again at sophos.

     

     

    BR

    Sebastian

     

Reply
  • Hi Bob,

    BAlfson said:
    Muß sagen - das stört mich.

    the same for me, can´t really believe this. But from the Real live perspective, If somebody would ask me, if I can agree with that statement, I would says yes. Just a short sum up of the last view major issues: See all the bugs in 1.) Sandstorm, 2.) scanning within compressed mail attachements, announced for 9.3, was not working (our customer found out), 3.) STAS--> Sophos has really no idea, how it works. It´s full of bugs without and not working properly in HA-mode, there´s even no concept for snycing the stas data between the nodes, it is not part of the sync. Means firewall does a failover and user based firewall rules are not working any more. 4.) Whats with all the FAILED updates with major impact? If we would sum up all of them, I think the list will be long 5.) I have also numerous other tickets, where it becomes clear, that in some cases, there is really bad documentation and even knowledge from sophos emloyees about a feature or functionality.

     

    Back to topic:

    The statement that I mentioned came from our distributor, when I talked to them last week regarding fixing the AD/SSO problem. Today I asked for more details about that statement. The contact at our distributor told me, that he got in touch with this statement two times. One time he heard this from a colleague of him, who was informed about this on one of the roadshows in 2017. The next time, he heard this himself while speaking to a sales territory manager. It was clearly said, that this is officical and thus can be communicated to partners (like us). But he wants to ask for clarification again at sophos.

     

     

    BR

    Sebastian

     

Children
No Data