This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Login with Captcha

I have just connected to an XG Firewall and as well as the user name and password and underneath is a captcha image with a box to type in response.

Haven't seen anything about that?



This thread was automatically locked due to age.
Parents Reply
  • [Updated - 5/7/2020 @ 4:50pm PDT]

    Hi All,

    Sophos added Captcha authentication to the admin and user portals on the WAN and VPN zones. This change only applies to XG Firewall v17.x and v18.x, except for XG85/XG85w devices. Any Cyberoam device that has upgraded to the XG Firewall firmware will not implement Captcha.

    This was implemented as an extra security defense against attackers attempting to script automated login attempts before customers had the opportunity to perform password resets; it’s also regarded as a best practice. The use of Captcha is currently not a policy-controlled option. Admins will see Captcha even if multi-factor authentication is enabled.


    Florentino
    Community Manager, Support & Services

    Support Videos | Product Documentation@SophosSupport | Sign up for SMS Alerts
    If a post solves your question, please use the 'Verify Answer' button.
Children
  • FloSupport said:

    Sophos added Captcha authentication to the admin and user portals when they are exposed on the WAN interface.  

    As already mentioned by other users: these seems not to be the only criterias for adding Captcha authentication. I also get this on firewalls where neither admin nor user portal is exposed on WAN interfaces. So there must be some more reasons. 

     

    FloSupport said:

    This change only applies to XG Firewall v17.x and v18.x

    Generally or only on firewalls on which data exfiltration has been performed?

  • I for one, would be happy to see the captcha permanently regardless of exposure on WAN

    Just an extra step for security and ‘peace of mind’

  • I won't disagree with you, another security step is a good mesure....
    But, this wouldn't be done without advanced information.

    Regarding the Captcha JC Sophos,  you got an Android App and a IOS App for your Authenticator.
    I use it to access Sophos Central, it's too much to ask to do the same thing?

  • Hi there,

    See my updated post above that includes additional details.

    Note: The KBA has also been updated to include this info.


    Florentino
    Community Manager, Support & Services

    Support Videos | Product Documentation@SophosSupport | Sign up for SMS Alerts
    If a post solves your question, please use the 'Verify Answer' button.
  • On one of my Firewall catcha do not appeared.  I entered the command manualy and rebooted the firewall

    But still NO captcha.

    Paul Jr

  • Ok.  Let's resume.

    On firewall 1/3.  Captcha enabled by latest update and working.

    On firewall 2/3.  Captcha manualy enabled via CLI since update did not enabled it, fail to work.

    On firewall 3/3.  Captcha enabled by latest update but fail to work.

    This is as inconsistent as it could be.

    Paul Jr

  • Checked this morning.  Still the same inconsistent result.  

    Paul Jr