This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Connection Resets/Drop off with AD Sync/STAS Enabled

This is an on-going issue we have had for a couple of months now. Support have been in our system watching. We have pretty much confirmed the cause at our end, but want to see if anyone else has experienced this.

Our setup is an X210 with STAS enabled without the Auth Client installed.

Our rules do not have user-based policies enabled.

What we see are consistent dropouts on the network when firewall authentication is enabled at the service level. When this is removed, the issue goes away. We have confirmed this on one other site with a very similar setup.

Any ideas?



This thread was automatically locked due to age.
Parents
  • ** Bump. A couple of subscribers to this, so I'm sure other people are having the issue.

    If we disable STAS, the issue goes away.

  • We have a similar issue. If you login to the advance shell, run "drppkt | grep 'Identity'" and see if you have any drops. I had a conversation with  and this was an unknown carryover from Cyberoam. The firewall is looking to authenticate the traffic even if the rule is not user based. It should be fixed in V17.2 hopefully. It is being tracked as NC-26440. You can disable STAS completely to get rid of the issue all together or you can change the time for "learning" on the XG to reduce the issue.

    Mike

  • We're seeing this as well.  IN particular it's a pain in the butt (even with 1 second learning time.)   We would like to get users names in the logs/reports using STAS, but when packets are dropped breaking our remote desktop traffic it becomes a huge pain.   All our fw fules are not user authenticated at all.  Thanks for the Bug tracking number.  I will also submit a ticket as well and reference that.

     

    Thanks,

    -Scott

Reply
  • We're seeing this as well.  IN particular it's a pain in the butt (even with 1 second learning time.)   We would like to get users names in the logs/reports using STAS, but when packets are dropped breaking our remote desktop traffic it becomes a huge pain.   All our fw fules are not user authenticated at all.  Thanks for the Bug tracking number.  I will also submit a ticket as well and reference that.

     

    Thanks,

    -Scott

Children
No Data