This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

V17.5 user sync with Sophos Central EDR EAP no users listed in live users view?

I am running a licenced XG v17.5 instance and my endpoint has Central EDR Eap running but im not seeing any users in the Live users view.  I was under the impression that I should see users there that were reported from the Heartbeat sync?

What am i missing?

JK



This thread was automatically locked due to age.
  • We do have an issue if the username has a dot . Could you let us know if that is the case with your and also share you log viewer for Authentication componenet.

  • User name does not have a dot

    There is nothing in the Authentication log!

  • In the syetm log, every 5 minutes this appears - Failed to send firewall information from device to CM


    I believe that you do not need to activate the firewall rule for device, but if I do the endpoint still does not show up. If, I put tick in box for Show Captive Portal for unknown users', I am presented with a login screen when accessing the internet, enter domain user name and password, which verifies, then this endpoint is send in 'Live Users'.

    So the AD part must work to verify (if I put wrong password in it fails). What appears logical to me is, the Endpoint is not passing forward the login detail from within Security Heartbeat.

  • My usernames have dots in them and its ok for me,

  • Hello all,

    I am using XG v17.5 with Intercept-X EAP and I have setup heartbeat, but it is acting a little bit strange.

    First of all, when I log into my computer with credentials DOMAIN\username, the heartbeat authentication doesn't work at all and in XG authentication logs I can see "username" failed to login because of wrong credentials. There is no mention of DOMAIN anywhere in that log.

     

    When I log into computer with credentials username@domain, heartbeat authetication works, at least for the first 30 minutes (the credentials in logs are also in format username@domain). Everytime after 30 minutes after the first login the heartbeat fails and in the logs I see credentials just stating "username" with no domain failed to login because of wrong credentials. This also happen when I disconnect/reconnect the computer from the network.

    Has anyone else experienced this issue?

  • Although I am yet to see any sign of 'Live Users', I can confirm a couple of things.

    If I use the firewall rule and turn on match Known users with show portal to unknown users, then use a web browser from Endpoint, I am offered the login.

    If I deliberate enter wrong password it fails (as expected) and AD server informs me of failed login, so I know AD side is working. But, as you say, when you login, within authentication log, it does show the user in the format of name@domain and not the user name you used. For me, it does not recognise domain\user, I just have to enter a domain user name without the domain.

  • I am advised that Security Heartbeat is picking up the user, but not the domain!

    For this particular Endpoint, it is a virtual machine and I am running MSTSC to connect to it. Once connected (using domain\user) and go to cmd prompt and run set, it clearly shows both the domain and user name correctly.

    Any ideas?

  • Hi Paul,

    True it will look for user details.  In order to acheive this settings the following conditions must be met..

    1. The Sophos Central Account must be linked to Sophos XG firewall.

    2. The XG firewall must be connected to the domain controller for authentication.

    3. The Users in the Central must have the same Profile. e.g. In the Central account if the user Domain/Username instead of Normal User then their profile must contain the Email address .

    4. Same Can be said on the local users on Sophos XG , use the Email address same as mentioned in the Central Profile.

    On the Endpoint you may check the username on the Sophos Endpoint UI> About > Run Diagnostics tool. > System

  • I can confirm 1-4 above are correct.

    I can also confirm checking (Sophos Endpoint UI> About > Run Diagnostics tool. > System) it indeed confirms both the domain\username


    But still not show in Live Users


    The Sophos Support engineer (with case [#8526233]) has highlighted that the Heartbeat does not include the domain name when it receives info


    2019-01-02 17:36:26 DEBUG HBSession.cpp[2758]:176 handleHeartbeatRequest - Received login request with id 147
    2019-01-02 17:36:26 DEBUG LoginRequestHandler.cpp[2758]:71 handleExtendedRequest - Ignoring login from local user in ModuleLogin: domain field in LoginRequest is empty