This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

V17.5 user sync with Sophos Central EDR EAP no users listed in live users view?

I am running a licenced XG v17.5 instance and my endpoint has Central EDR Eap running but im not seeing any users in the Live users view.  I was under the impression that I should see users there that were reported from the Heartbeat sync?

What am i missing?

JK



This thread was automatically locked due to age.
Parents
  • Yes ive followed all the documentation i could find on the matter, from what i gather i should see usernames under the Live users view shouldnt I?  They should be sent from the Central Endpoint right?  From what i read i assumed that i should see the usernames there whether Ive got my XG linked to AD or not because Endpoint sends a username, is that right?  

    Also I know XG and Central is sending some kinda usernames from my logs: -

    Ive tried to add a user matching what i use to logon with but it didnt seem to work, i still get failed errors.

    Should i see that user in the live users view if it fails or not??

    See i cant add AD to my XG as i logon with AzureAD, but from those logs i assumed i could use local users on my XG but obviously not?

    Thanks for your reply,

    JK

  • That shows ur Heartbeat user id sync is ok, are you able to manage your XG from the new Central firewall management EAP??  Again im only guessing but im sure i read somewhere that you also need to join that Central Firewall management EAP for user id to work??

    If your not in it you can join that EAP from the Early Access Programs drop down item on centrals username menu.

    As to XG and Modem mode, it basically means your XGs WAN int is facing the internet directly rather than being NATed again as you had your XG and draytek setup before.  Without modem mode you need to port forward or use a DMZ for all traffic to the WAN int on your Draytek, also without modem mode your Drayteks firewall features would be on and then you would have 2 firewalls that could cause problems.

    Basically for what i can tell it boils down to whether you want to use your XG in Bridge mode or Gateway mode, In bridge mode you could use your Draytek as your main router again but you lose quite a few of XGs features

    Bridged Interfaces do not support the following features:

    1. Dynamic DNS
    2. Multicast Routing
    3. DHCP Client
    4. IPsec VPN
    5. VLAN
    6. Virtual Host
    7. PPPoE
    8. Bridge (a Bridged Interface cannot be a member of Bridge)

    Quoted from https://community.sophos.com/products/xg-firewall/f/initial-setup/93224/setup-behind-wireless-modem-router-gateway-or-bridge

     

  • Yes, within Central, I can see and manage my Firewall!

    I think now, I will wait for support to assist further with the case I have open. Its been well worthwhile with this thread and have advanced further but not yet resolved.

    If anyone has any other ideas, they are welcome. I will update further if and when resolved.

  • Yeah Support is your best bet now, when you resolve the issue please post what Sophos Support did to resolve it id be interested to know myself for future reference.

    Sorry couldn't be of more help myself.....

  • Hi  

    I've located your support case and I have followed up with your assigned engineer.

    As per the email exchange, kindly organize a time for a remote access troubleshooting session to be performed.

    Please PM me directly if you had any questions regarding your support case.

    Thanks,

  • Yes - we are already communicating this evening - thanks

  • Did you get this sorted Paul?  Be interested to know what your issue was but my user id heartbeat popped to life as soon as my XG instance was authenticating against the same Azure AD directory my Sophos Central was albeit via JumpClouds LDAP which in turn was syncing from the same source Azure AD / Office 365 Directory.  Have you gone over your AD sync on You Sophos Central instance and AD config on your XG instance?  I didnt expect my XG instance to actually show my Azure AD users when i added JumpCloud LDAP to my XG i was aiming at something completely different but was surprised i had fixed my User ID auth via Heartbeat by solving a different Auth Based problem i was having. 

    But As soon as i Added the LDAP server to XG it all started working.

    So maybe start at the beginning and work through your Central AD Sync, XG AD server inc making sure your xgs authentication source is first your AD server and not local authentication.  Lastly making sure your Endpoints are correctly authenticating against the same AD Servers??

  • No not sorted, Ran out of time to go through with Sophos Support New Years Eve, but will be doing so Wednesday.

  • No not sorted, Ran out of time to go through with Sophos Support New Years Eve, but will be doing so Wednesday.

    As far as I understood with v17.5 + Central, there is no need to setup AD sync, other than on XG? The Heartbeat is supposed to pickup the login and pass information to GX

  • It is correct. You do not need any user in Central.

    Basically, the Endpoint daemon will pick up Domain, Username and send it to XG. XG will perform the lookup to check the user and that is it. 

  • Thanks for confirmation - thought I was 'going mad'!!!

    Does the log below from heartbeat.log on Endpoint confirm that it is passing the login info? From your earlier reply, looking at logs on XG is not something I am comfortable with and will await Sophos Support to assist with


    a 2018-12-30T11:48:19.352Z [2432:2580] - Starting Heartbeat version 1.8.59.0
    a 2018-12-30T11:48:19.352Z [2432:2580] - ----------------------------------------------------------------------------------------------------
    a 2018-12-30T11:48:20.413Z [2432:2720] - Connection succeeded.
    a 2018-12-30T11:48:20.413Z [2432:2720] - Connected to 'xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx' at IP address xxx.xxx.xxx.xxx on port xxxx
    a 2018-12-30T11:48:20.507Z [2432:2720] - Sending network status. Active Interfaces:
    MAC: xx:xx:xx:xx:xx:xx - INET: xxx.xxx.xxx.xxx - INET6: xxxx::xxxx:xx:xxx:xxxx
    a 2018-12-30T11:48:20.538Z [2432:2720] - Received request to enable enhanced application control
    a 2018-12-30T11:48:20.538Z [2432:2720] - Sending endpoint state list request
    a 2018-12-30T11:48:20.538Z [2432:2720] - Sending login status.
    a 2018-12-30T11:48:20.538Z [2432:2720] - Received response to endpoint state list request, size: 0
    a 2018-12-30T11:48:21.895Z [2432:2720] - Sending health status: {"admin":1, "health":1, "service":1, "threat":1}
    a 2018-12-30T11:49:21.307Z [2432:2720] - Sending login status.
    a 2018-12-30T11:49:54.125Z [2432:2720] - Received notification of endpoint state changes, size: 1
    a 2018-12-30T11:50:53.128Z [2432:2720] - Received notification of endpoint state changes, size: 1
    a 2018-12-30T11:51:59.583Z [2432:2720] - Received notification of endpoint state changes, size: 1
    a 2018-12-30T11:52:14.597Z [2432:2720] - Received notification of endpoint state changes, size: 1
    a 2018-12-30T15:17:22.571Z [2432:2720] - Sending login status.
    a 2018-12-30T15:17:52.575Z [2432:2720] - Sending login status.

Reply
  • Thanks for confirmation - thought I was 'going mad'!!!

    Does the log below from heartbeat.log on Endpoint confirm that it is passing the login info? From your earlier reply, looking at logs on XG is not something I am comfortable with and will await Sophos Support to assist with


    a 2018-12-30T11:48:19.352Z [2432:2580] - Starting Heartbeat version 1.8.59.0
    a 2018-12-30T11:48:19.352Z [2432:2580] - ----------------------------------------------------------------------------------------------------
    a 2018-12-30T11:48:20.413Z [2432:2720] - Connection succeeded.
    a 2018-12-30T11:48:20.413Z [2432:2720] - Connected to 'xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx' at IP address xxx.xxx.xxx.xxx on port xxxx
    a 2018-12-30T11:48:20.507Z [2432:2720] - Sending network status. Active Interfaces:
    MAC: xx:xx:xx:xx:xx:xx - INET: xxx.xxx.xxx.xxx - INET6: xxxx::xxxx:xx:xxx:xxxx
    a 2018-12-30T11:48:20.538Z [2432:2720] - Received request to enable enhanced application control
    a 2018-12-30T11:48:20.538Z [2432:2720] - Sending endpoint state list request
    a 2018-12-30T11:48:20.538Z [2432:2720] - Sending login status.
    a 2018-12-30T11:48:20.538Z [2432:2720] - Received response to endpoint state list request, size: 0
    a 2018-12-30T11:48:21.895Z [2432:2720] - Sending health status: {"admin":1, "health":1, "service":1, "threat":1}
    a 2018-12-30T11:49:21.307Z [2432:2720] - Sending login status.
    a 2018-12-30T11:49:54.125Z [2432:2720] - Received notification of endpoint state changes, size: 1
    a 2018-12-30T11:50:53.128Z [2432:2720] - Received notification of endpoint state changes, size: 1
    a 2018-12-30T11:51:59.583Z [2432:2720] - Received notification of endpoint state changes, size: 1
    a 2018-12-30T11:52:14.597Z [2432:2720] - Received notification of endpoint state changes, size: 1
    a 2018-12-30T15:17:22.571Z [2432:2720] - Sending login status.
    a 2018-12-30T15:17:52.575Z [2432:2720] - Sending login status.

Children
No Data