This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

V17.5 user sync with Sophos Central EDR EAP no users listed in live users view?

I am running a licenced XG v17.5 instance and my endpoint has Central EDR Eap running but im not seeing any users in the Live users view.  I was under the impression that I should see users there that were reported from the Heartbeat sync?

What am i missing?

JK



This thread was automatically locked due to age.
Parents
  • Yes ive followed all the documentation i could find on the matter, from what i gather i should see usernames under the Live users view shouldnt I?  They should be sent from the Central Endpoint right?  From what i read i assumed that i should see the usernames there whether Ive got my XG linked to AD or not because Endpoint sends a username, is that right?  

    Also I know XG and Central is sending some kinda usernames from my logs: -

    Ive tried to add a user matching what i use to logon with but it didnt seem to work, i still get failed errors.

    Should i see that user in the live users view if it fails or not??

    See i cant add AD to my XG as i logon with AzureAD, but from those logs i assumed i could use local users on my XG but obviously not?

    Thanks for your reply,

    JK

  • Paul Digby said:

    Failed to send firewall information from device to CM

     

    I think thats whats hanging you up but im not sure how to resolve that error?  do you have a router in front of your XG on your WAN port or a router setup in modem mode?

  • There is a router in front of XG.

    It basically is just used for internet connection and all incoming traffic gets forwarded to XG and any traffic received from XG goes out to internet

  • No = If you see failed logins in XG logviewer by HB - only information that shows under Heartbeat in Log Viewer is the entry that shows endpoint health

    No = EP is sending the Username (SAMAccountname) and Domain - I don't believe that it is

  • That could be why XG isnt sending heartbeat to Central, have you tried putting the router in modem mode??  

  • What is 'modem mode' and how would you do that? What am I looking for?

  • I have found a page on my Draytek 2862 and there is an option for PPoE Pass-through, with an option to check 'for Wired LAN'.

    There is a note at the bottom that advises, the router will behave like a modem, which only serves the PPoE client or the LAN.


    If I make this change, anything to change of the XG?

  • Should ask first do you have XG in Gateway mode or Bridge mode?? If its in bridge mode You may not need to do this after all.

    You will need to setup the WAN interface on XG to PPPOE aswell and youll need your ISP username & password for the PPPOE connection (your isp will supply this over the phone if you dont have that)

    So make sure you have the PPPOE credentials, put the draytek into modem mode (pppoe passthrough) then on XG change the WAN interface to PPPOE and provide the credentials.  When you save that XG should connect via PPPOE, youll see your EXT ip on the WAN Interface when its connected.

    Hopefully that should sort the XG to Central communication, FYI you will lose the WIFI on the Draytek in PPPOE passthrough mode.  Basically having your Draytek in router mode on the WAN interface Double NATTING, putting your router into Modem mode / pppoe passthrough mode does away with that so you have a single NAT setup.

  • Thanks for explanation. I have the Login details, so no worry there.

    However, does this make this setup less secure? What I mean is, the Draytek gets its public IP, then the Draytek and XG connect on a different subnet, which is different to the LAN subnet.

  • Its not More or Less secure to what you have now, In PPPOE passthrough mode your draytek basically becomes a modem and drops its router functions.  Then XG takes over those roles on your LAN.  If your XG is already in Gateway mode then your LAN interface and network wont need to change as its just the WAN interface that changes as it gets a public IP directly rather than an IP from the draytek when then NATs the traffic again.

    Ive got my XG setup with my Virgin Router in Modem mode.

    Its worth trying to see if it resolves your Central communications?  (Also in my opinion its the prefered way to have your XG setup)

  • Quick Update - struggling to get Draytek in modem mode and XG to connect. XG does not move off connecting.

    I know user name and password are correct as I manually typed back into Draytek when returned to normal. Must be something else on Draytek I overlooked.

    Further update UK time 17:00

Reply
  • Quick Update - struggling to get Draytek in modem mode and XG to connect. XG does not move off connecting.

    I know user name and password are correct as I manually typed back into Draytek when returned to normal. Must be something else on Draytek I overlooked.

    Further update UK time 17:00

Children
No Data