Hello All,
I am new to this community - I have inherited a Sophos Virtual Web Appliance, set up in transparent mode for the network I now manage.
I have been taking time to reverse engineer the configurations, and have slowly been learning how my predecessor set up the infrastructure (little to no documentation)
In any case, they currently run RADIUS for authentication in Wifi and through the VWA. These policies work properly, and users are filtered correctly.
However, I need to deploy some mobile devices which do not play nice with RADIUS. I have created an SSID on the AP's, tied it to a VLAN, and set up routing for the VLAN.
I can access the internet, however the VWA is filtering the traffic for this VLAN with the Default policy, and not the new IP-Based policies I have created.
Essentially:
Under Group Policy -> Additional Policies.
--Mobile Devices
---Manual Entries: 10.8.0.0/21 (IP range for the VLAN)
---Schedule: All the time
---Turn this policy on for machines connecting from anywhere
As well, in System -> Authentication -> Profiles
--Mobile Devices:
---Manual Entries: 10.8.0.0/21
---Authentication: Bypass Authentication (use IP-based policy rules)
And in Connection Profiles:
--Mobile Devices
--- Include only the selected IP's in this profile: 10.8.0.0/21
I have checked the other policies in place for servers, guest network, etc - it seems I have everything configured the same, but these policies for this VLAN do not work.
I have tested it by placing several devices on the VLAN, as well as using the Policy Test tool under Group Policy.
Can anyone perhaps provide some insight as to why this doesn't work?
This thread was automatically locked due to age.