In UTM 9.1 we are using samba-3.6.4-2.
We have confirmed that the UTM can join to a AD 2012r2 server.
Please note that the UTM does not necessarily use resolv.conf and hosts files. You should be using the WebAdmin console for editing that stuff.
What happens if you just:
dig pps.local
Also, is there anything interesting in named.log?
I hope I am not jumping the gun but I'm 99.99% sure I have a workaround for this. The Sophos UTM only supports SMB1.0/NTLMv1 (this can be seen in it's SMB ComNegotiate packet it sends to the domain controller on a domain join attempt). LanmanServer in 2012r2 depends on SMB2.0 as a minimum.
Unfortunately until the UTM supports SMB2.0 properly you will have to set your 2012r2 domain controllers to support SMB1.0. This can be done by following this blog Windows XP Clients Cannot Execute Logon Scripts against a Windows Server 2012 R2 Domain Controller – Workaround | Working Hard In IT
I hope this helps someone else.
Regards
Matt
Yes, I know this is an old thread, but the problem is still relevant. After disabling SMB v1 on servers yesterday in response to closing vulnerabilities that WannaCry ransomware takes advantage of, authentication for web filtering starting breaking. Long story short, even today 2017 running UTM 9.500-9, UTM 9 is STILL USING SMB V1! Come on Sophos, this needs to be fixed.
With smbv1 disabled on AD servers, the UTM cannot join the domain. As soon as you re-enable SMBv1, the domain join works fine.
Yes, I know this is an old thread, but the problem is still relevant. After disabling SMB v1 on servers yesterday in response to closing vulnerabilities that WannaCry ransomware takes advantage of, authentication for web filtering starting breaking. Long story short, even today 2017 running UTM 9.500-9, UTM 9 is STILL USING SMB V1! Come on Sophos, this needs to be fixed.
With smbv1 disabled on AD servers, the UTM cannot join the domain. As soon as you re-enable SMBv1, the domain join works fine.
Please open a support ticket, James.
In fact, everyone should do this now if you have a similar problem.
Cheers - Bob