This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

After updating to 9.501-5 SSO for HTTP authentication failed and domain join not working.

UTM 9.501-5

Windows server 2012 domain controller.

I installed the 9.5 update on June 2, did not see any issues with this for the client, updated to 9.501-5 on June 12 midnight, and Internet access is failing on multiple sites.

Can get to Google.ca

Cannot get to canada411.com - Too many http redirects message.

Turned off web filtering and the websites were available - but the client requires filtering.

Re-enabled and turned off AD SSO authentication and websites are available again with correct content being blocked.

Attempted to remove from and rejoin domain, but domain join failed.

 

Currently, I have the client functioning, but, I need to rejoin AD and resume SSO authentication.

 



This thread was automatically locked due to age.
  • I upgraded to 9.502-4 last night had ran into some issues with not being able to rejoin my UTM to the domain. After deleting the old entry for the firewall and forcing replication, I was able to join my UTM to the domain. Even after forcing replication, it took about 5-10 minutes before I could rejoin the UTM to the domain. However, it created an entry in DNS for each interface in the UTM. Now there were multiple clients having issues browsing the Internet. The issue was caused by the multiple entries. I deleted all the entries except for the one that pointed to the internal IP address for the UTM.

    Now all the clients can browse the Internet with no issues.

    Hopefully, this information might help someone else out.

    Regards,

  • I am in the same boat. I called sophos support multiple times and no one even mentioned rejoining the domain. They did not mention anything from this forum.  Things work for a bit then no one can access anything. A reboot of both UTMs in the HA are necessary and this fixes it for a short time most of the time but the issue has been present every day since we ran these updates. I am at the latest update also. 9.502 -4

     

    Very disappointed with our new sophos utms since the update.  School is about to start and we will have 10,000 people here all with struggling internet connections because of this update. 

  • It finally works again for us. We did the following things in this order:

    - Firmware Update to 9.503 from this page, at the moment only by FTP available:
    community.sophos.com/.../utm-up2date-9-503-released

    - delete AD computer object of Sophos UTM
    - Do a failed Domain join at Definitions & Users -> Authentication Services -> Single Sign-On: fill in correct domain, but wrong username and password. Status should change to failed. Then join your domain again with correct login data, status should "Joined Domain".
    - reboot your Sophos UTM
    - users have to log off their computers and login again
    - if you had your Sophos hostname in your Internet Explorer proxy settings: change it to ip. Like 172.17.0.123:8080 in our case.

  • Hi, and welcome to the UTM Community!

    Your final step has the effect of causing the UTM to do SSO user authentication with NTLM instead of Kerberos.  Did you find that there was no function until you made that change?  Note that, depending on the hardware in use, joining can take (what feels like) five to ten minutes.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thank you!

     

    Yes, it was instantly working when the setting was changed to ip. If not, a browser error message appears: "authentication failed". It comes today as well, when I change it back to hostname. So this problem might not be completeley fixed at Sophos firmware yet?

  • Hi,

    I Came up with the same issue for one of our client after tge firmware upgrade, after scratching my head out for an hour I found out that though I had synchronized the time with NTP, the sync didnt take place right away and the time on the UTM was still different to that of the NTP or the so called Active directory domain controller. I had to manually change the time on UTM master and reboot the device. It worked like a charm.

    (Also I had removed the existing computer name for this UTM from the Active Directory Domain before I tried to join the UTM back after i made changes to the time).

  • Up until today I am still trying to switch back to Kerbereos authentication, it just does not work anymore, even in 9.509-3

  • Kerberos works fine in 9.509 for all of my clients and in my lab.  You will want to use an FQDN in your browsers' explicit proxy setting.  See Configuring HTTP/S proxy access with AD SSO.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA