ZTNA has stopped working ... possible after uploading new certificates.
- open "fhem.ztna.mydomain.de" Authentication is triggered but afterwards i got a black screen
- redirect to AZURE-Auth -- authenticating (i try different users)
- redirected to "gw.ztna.mydomain.de" -> black screen
central say gateway is connected (tried restarting the firewall 24 minuted ago)
Where can i check what's happened?
hi dirkkotte
Thanks for reaching out, we checked error logs for your account. We found that your Identity provider creds are expired. Request you to please update the same. After updating creds, you can check if they are valid by doing Test connection
https://docs.sophos.com/central/ZTNA/startup/en-us/setup/IdentityProvider/index.html
You would also need to update your central Directory Sync settings, as we see from error logs , even those creds are expired
Thanks.
After updating creds it works again.
Is there an option to check the error logs by myself?
Would be great you generate an alert within ZTNA for this problem.
Dirk
Systema Gesellschaft für angewandte Datentechnik mbH // Sophos Platinum Partner
Sophos Solution Partner since 2003
If a post solves your question, click the 'Verify Answer' link at this post.
Hi,
I am able to open, Authenticate and use the agentless apps.
But the agent (from same device) say "Failed to create connection. Server certificate validation error gw.ztna.mydomain.de, due to: certificate verify failed (SSL routines) " in "Sophos EndPoint self help / ZTNA"
Can't find some SSL or certificate-problems from within browser.
PS: The link behind the messages is dead:
Dirk
Systema Gesellschaft für angewandte Datentechnik mbH // Sophos Platinum Partner
Sophos Solution Partner since 2003
If a post solves your question, click the 'Verify Answer' link at this post.
Hi dirkkotte
Thanks for sharing the information about the new error.
We see that ZTNA Gateway hasn't received the renewed cert as your ZTNA license was expired at time of renewal. Its a known issue, We will try to apply a workaround which would help unblock you, I will reach out once this is done so that you can verify
Also the KB article link should redirect to https://support.sophos.com/support/s/article/KBA-000008084?language=en_US#link2
Ok, thanks.
It is not a problem for me to add the certificate a second time ... should i do this?
Dirk
Systema Gesellschaft für angewandte Datentechnik mbH // Sophos Platinum Partner
Sophos Solution Partner since 2003
If a post solves your question, click the 'Verify Answer' link at this post.
No its not related to wild card cert you upload for the gateway. its internal certificate chain used for mutual TLS between gateway and endpoint
dirkkotte
We have applied the workaround from backend, Issue should now be fixed, Please check and let us know if you are able to access the Agent based resources now
same problem:
Dirk
Systema Gesellschaft für angewandte Datentechnik mbH // Sophos Platinum Partner
Sophos Solution Partner since 2003
If a post solves your question, click the 'Verify Answer' link at this post.
We need the SDU from the endpoint to check on the issue. You can reach out the Sophos Support or alternatively you can use the “Feedback” option within ZTNA Sophos Central along with your email and other details.
Today it works.
Possible, the last reboot of the LAB-VM solved the problem. I started yesterday multiple times too.
Thanks a lot !!
Dirk
Systema Gesellschaft für angewandte Datentechnik mbH // Sophos Platinum Partner
Sophos Solution Partner since 2003
If a post solves your question, click the 'Verify Answer' link at this post.