This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

V17.5 user sync with Sophos Central EDR EAP no users listed in live users view?

I am running a licenced XG v17.5 instance and my endpoint has Central EDR Eap running but im not seeing any users in the Live users view.  I was under the impression that I should see users there that were reported from the Heartbeat sync?

What am i missing?

JK



This thread was automatically locked due to age.
Parents
  • Yes ive followed all the documentation i could find on the matter, from what i gather i should see usernames under the Live users view shouldnt I?  They should be sent from the Central Endpoint right?  From what i read i assumed that i should see the usernames there whether Ive got my XG linked to AD or not because Endpoint sends a username, is that right?  

    Also I know XG and Central is sending some kinda usernames from my logs: -

    Ive tried to add a user matching what i use to logon with but it didnt seem to work, i still get failed errors.

    Should i see that user in the live users view if it fails or not??

    See i cant add AD to my XG as i logon with AzureAD, but from those logs i assumed i could use local users on my XG but obviously not?

    Thanks for your reply,

    JK

  • Hi  

    "Synchronized User ID will share domain user account information from the client machine the user is logged into with the firewall via Heartbeat. The Firewall will then check the user account against the configured AD server and activates the user. Synchronized User ID will only work with Active Directory configured as an authentication server in XG Firewall and it is currently supported for Windows 7 and Windows 10 machines. No agents are required on the server or clients, nor does it share or utilize any password information. Synchronized User ID does not work with other directory services, and it will not recognize local users."

    You will be able to see local users on your XG live users list, if you have configured a firewall rule that performs authentication via the captive portal.

    Regards,

  • Sync User ID needs an configured AD server.

    Local User does not work.

    "It only requires that the Active Directory server is configured as an authentication server in XG Firewall."

  • Oh well i knew that an AD server would be required to perform auth based tasks but i was at least hoping that the endpoints Heartbeat would at least inform XG of the username from that IP to be displayed in Live users.

    Looks like its back to the Auth Agent.

    Is AzureAD based authentication method anywhere on the horizon as a new feature??  

    Thanks

  • I have exactly the same problem, except I do have a Windows AD Server configured and using Win7 + Win 10. Yet, not seeing Live Users!

    I also have a Support Case ([#8526233), if FloSupport or Lucar Toni want to take a look

     

     

  • Are you seeing anything in your Authentication Logs on your XG?  That will be a big help in diagnosing the problem.  Also have you added your AD DC's to your XG and imported users / groups from AD?  

    If you could post any logs your getting in your Auth logs i might be able to help out.  Ive actually gotten a clients synced user ID working via on premises AD just not with Azure AD like my original post relates too.

Reply
  • Are you seeing anything in your Authentication Logs on your XG?  That will be a big help in diagnosing the problem.  Also have you added your AD DC's to your XG and imported users / groups from AD?  

    If you could post any logs your getting in your Auth logs i might be able to help out.  Ive actually gotten a clients synced user ID working via on premises AD just not with Azure AD like my original post relates too.

Children
  • Yes - under Authentication, Servers, AD server is listed and have imported users.

    No - nothing showing under authentication

    Yes - there is a rule for the computer I test with Match Known users

    Yes - there are security heartbeat events for this computer showing in Log


    Its as if, the user information is not being collected / passed forward within the Security Heartbeat function. If I put 'tick in box' for show portal for unknown users, and login with valid AD user, I can login and then user shows in 'Live Users'

    But that's not the point, it should auto vaidate

  • Do you have NTLM and Client Auth enabled under Administration - Device Access, For your LAN?  I know AD auth used to require NTLM but it shouldnt need it with the Endpoing Agent installed.  Are you in the Central Endpoint EDR Eap??  That is needed for User ID to work at the moment.  Also under Central Synchronization - Security Heartbeat Optional Config Do you have Lan Added as Missing Heatbeat Zones??  That is needed if you want Heartbeat to work on the LAN without needing to add the Heatbeat settings on all your Firewall Rules?

    Also Do you have all the Events Logging options enabled?  Check your Authentication Event logging is enabled as you should be seeing some sort of Auth log events?

  • No = NTLM
    Yes = Client Authentication

    Yes = Are you in the Central Endpoint EDR Eap

    No = Do you have Lan Added as Missing Heatbeat Zones (Just added, no difference)

    Yes = Do you have all the Events Logging options enabled


  • First of all, Do you see anything in the live log, which could indicate, Security Heartbeat tries to authenticate somebody? 

     

    I assume, there is something "Wrong configured anywhere". Because for all customers this works fine, if everything is in place from day one. 

    So lets take a look. 

     

    If you see failed logins in XG logviewer by HB, this means, the EP is sending XG credentials, which XG cannot use to login this user. 

    EP is sending the Username (SAMAccountname) and Domain. This will be used by XG to lookup the user in AD. 

     

    I talked about this process in more detail here.

    https://community.sophos.com/products/xg-firewall/f/authentication/109490/user-creation-from-portal-creates-a-user-account-with-email-addresse-name-containing-blanks/391924#pi2151=1

     

    Basically Sync User ID is another approach to use the Access_server (XG Authentication Daemon) to get the user in live users. 

    It should not need anything configured in any firewall rule to simply show the live users. 

  • Have you enabled NTLM? (although I dont think this is required as from what i understand the Endpoint Agent should be sending the Auth Data to XG)

    Also have you setup your AD in Sophos Central web admin aswell and imported your users there too?

    One other thing to check is on your XG are your endpoints showing as connected under security heartbeat?  Also in your Firewall logs add a filter for Log comp then select Heartbeat in the dropdown.  That will show you if your Heatbeat traffic is failing or not, also another log entry to check is under System logs which will show Central Management Events.  Is that failing?

  • Yes = Have you enabled NTLM - but made no difference

    No = have you setup your AD in Sophos Central web admin aswell and imported your users there too

    Yes = are your endpoints showing as connected under security heartbeat

    Yes = System Logs I see many entries as follow


    Failed to send firewall information from device to CM





  • Paul Digby said:

    Failed to send firewall information from device to CM

     

    I think thats whats hanging you up but im not sure how to resolve that error?  do you have a router in front of your XG on your WAN port or a router setup in modem mode?

  • There is a router in front of XG.

    It basically is just used for internet connection and all incoming traffic gets forwarded to XG and any traffic received from XG goes out to internet

  • No = If you see failed logins in XG logviewer by HB - only information that shows under Heartbeat in Log Viewer is the entry that shows endpoint health

    No = EP is sending the Username (SAMAccountname) and Domain - I don't believe that it is

  • That could be why XG isnt sending heartbeat to Central, have you tried putting the router in modem mode??