This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Directory Services synchronization (SSO & AD)

Some people have been having issues with SSO and AD synchronization.  I'm just reporting my issue and to document.

2 x UTM525's in HA.  We're using SSO for users, all the goodies, web filtering, email, VPN, user portal.

After upgrading to 9.313-3 on Tuesday started getting the below alerts.  Our UTM service account keeps getting locked out about every 2 hours on the dot.

Error message:
---------------------
[WARN-531] Directory Services synchronization
There was an error synchronizing subscribed groups. The Sophos UTM will continue to operate with a locally cached copy of the data but will be unable to update from Directory Services until the issue is resolved.

Error was:
failed to run samba command on domain.com, exiting now
--------------------

Tried un-joining and re-joining UTM to our domain, still have issues.  Tests on server settings come back fine.  User authenticate test come back fine.

So anyone else having this issue as well?  Waiting for Sophos support to call back to help troubleshoot.  A little off-topic/rant but Sophos support REALLY needs some improvement.  It takes like 20-30 minutes just to put a ticket in and I've been waiting for over 90 minutes for an engineer call back (after being told I would get a call back in 30 minutes).


This thread was automatically locked due to age.
Parents
  • Did you un-join by trying to join with incorrect credentials from within WebAdmin?

    I think we're getting near the end of the issues that began last year, but you might try a restore of the config backup created before the Up2Date.  If that doesn't resolve the issue, you might try rebooting the Slave, waiting until it has synced and then rebooting the Master.

    There was supposed to be a fix in 9.313 for a false alarm of this notification.  Did you check to see if the groups are updated?  If so, and none of the above helped, maybe the fix didn't get into 9.313.  You could try Up2Dating to 9.315 or just disabling the 531 notification until you're ready.

    Cheers - Bob
    PS The fastest way to get help if you have Premium Support is to submit a case in MyUTM.  Next fastest is email.  Slowest is calling.  Using Standard Support and working with a knowledgeable Sophos Solution Partner is the fastest as many issues can be addressed in a quick conversation or email.
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • After updating to firmware 9.413-4 and 9.501-5 last night, I have started seeing this message every two hours starting at 4:39 AM. I applied the last firmware update at 8:45 PM on 6/13/2017.
    Pattern Version: 127636.
     
    Regards,
  • I received the same messages after Up2Dating to 9.414.  The Fallback log indicated failed to run samba command on our AD server.  The fix was to unjoin/rejoin on the 'Single Sign-On' tab.  Break the join by using incorrect credentials and then use valid credentials to rejoin.  Did that resolve your issue?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • I received the same messages after Up2Dating to 9.414.  The Fallback log indicated failed to run samba command on our AD server.  The fix was to unjoin/rejoin on the 'Single Sign-On' tab.  Break the join by using incorrect credentials and then use valid credentials to rejoin.  Did that resolve your issue?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children