This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

V17.5 user sync with Sophos Central EDR EAP no users listed in live users view?

I am running a licenced XG v17.5 instance and my endpoint has Central EDR Eap running but im not seeing any users in the Live users view.  I was under the impression that I should see users there that were reported from the Heartbeat sync?

What am i missing?

JK



This thread was automatically locked due to age.
  • First of all, Do you see anything in the live log, which could indicate, Security Heartbeat tries to authenticate somebody? 

     

    I assume, there is something "Wrong configured anywhere". Because for all customers this works fine, if everything is in place from day one. 

    So lets take a look. 

     

    If you see failed logins in XG logviewer by HB, this means, the EP is sending XG credentials, which XG cannot use to login this user. 

    EP is sending the Username (SAMAccountname) and Domain. This will be used by XG to lookup the user in AD. 

     

    I talked about this process in more detail here.

    https://community.sophos.com/products/xg-firewall/f/authentication/109490/user-creation-from-portal-creates-a-user-account-with-email-addresse-name-containing-blanks/391924#pi2151=1

     

    Basically Sync User ID is another approach to use the Access_server (XG Authentication Daemon) to get the user in live users. 

    It should not need anything configured in any firewall rule to simply show the live users. 

  • Have you enabled NTLM? (although I dont think this is required as from what i understand the Endpoint Agent should be sending the Auth Data to XG)

    Also have you setup your AD in Sophos Central web admin aswell and imported your users there too?

    One other thing to check is on your XG are your endpoints showing as connected under security heartbeat?  Also in your Firewall logs add a filter for Log comp then select Heartbeat in the dropdown.  That will show you if your Heatbeat traffic is failing or not, also another log entry to check is under System logs which will show Central Management Events.  Is that failing?

  • Yes = Have you enabled NTLM - but made no difference

    No = have you setup your AD in Sophos Central web admin aswell and imported your users there too

    Yes = are your endpoints showing as connected under security heartbeat

    Yes = System Logs I see many entries as follow


    Failed to send firewall information from device to CM





  • Paul Digby said:

    Failed to send firewall information from device to CM

     

    I think thats whats hanging you up but im not sure how to resolve that error?  do you have a router in front of your XG on your WAN port or a router setup in modem mode?

  • There is a router in front of XG.

    It basically is just used for internet connection and all incoming traffic gets forwarded to XG and any traffic received from XG goes out to internet

  • No = If you see failed logins in XG logviewer by HB - only information that shows under Heartbeat in Log Viewer is the entry that shows endpoint health

    No = EP is sending the Username (SAMAccountname) and Domain - I don't believe that it is

  • That could be why XG isnt sending heartbeat to Central, have you tried putting the router in modem mode??  

  • What is 'modem mode' and how would you do that? What am I looking for?

  • I have found a page on my Draytek 2862 and there is an option for PPoE Pass-through, with an option to check 'for Wired LAN'.

    There is a note at the bottom that advises, the router will behave like a modem, which only serves the PPoE client or the LAN.


    If I make this change, anything to change of the XG?

  • Should ask first do you have XG in Gateway mode or Bridge mode?? If its in bridge mode You may not need to do this after all.

    You will need to setup the WAN interface on XG to PPPOE aswell and youll need your ISP username & password for the PPPOE connection (your isp will supply this over the phone if you dont have that)

    So make sure you have the PPPOE credentials, put the draytek into modem mode (pppoe passthrough) then on XG change the WAN interface to PPPOE and provide the credentials.  When you save that XG should connect via PPPOE, youll see your EXT ip on the WAN Interface when its connected.

    Hopefully that should sort the XG to Central communication, FYI you will lose the WIFI on the Draytek in PPPOE passthrough mode.  Basically having your Draytek in router mode on the WAN interface Double NATTING, putting your router into Modem mode / pppoe passthrough mode does away with that so you have a single NAT setup.