This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Wireless SSO and Sophos AP's

Hi,

Is Wireless SSO supposed to "just work" with Sophos AP's?

As far as I can see there is a requirement that the client IP address is sent to the Sophos XG in the accounting packet, which is a bit tricky as if the device is using DHCP as it doesn't have an IP address at sign-in time, and possibly not until a number of seconds after.

Is there a KB article or something on how this process works with Sophos AP's?

I have WPA2 Enterprise working just fine, but the Sophos XG is still blind to who the users are.

Thanks

James



This thread was automatically locked due to age.
Parents
  • Not right now.

    The AP does not support radius framed ip address. But DEV is already working on this feature for the AP to support this.

    It is a limitation of the AP, not XG. If the AP would do this, it will perfectly work right now.

  • Thanks for the confirmation. Is this documented somewhere and I just missed it?

    Could you explain a bit how it will work? I think of a few ways that this could work:

    1. AP snoops the IP associated with the MAC and sends interim accounting packets
    2. XG snoops the IP associated with the MAC (only if on the same LAN segment, and would also work for 802.1x wired security))
    3. XG associates the user to the MAC instead of to the IP (only if on the same LAN segment, and would also work for 802.1x wired security)
    4. XG DHCP does the MAC->IP association when it hands out the DHCP lease (only if XG is DHCP server)

    Also is there an ETA on this feature?

    Thanks

    James

Reply
  • Thanks for the confirmation. Is this documented somewhere and I just missed it?

    Could you explain a bit how it will work? I think of a few ways that this could work:

    1. AP snoops the IP associated with the MAC and sends interim accounting packets
    2. XG snoops the IP associated with the MAC (only if on the same LAN segment, and would also work for 802.1x wired security))
    3. XG associates the user to the MAC instead of to the IP (only if on the same LAN segment, and would also work for 802.1x wired security)
    4. XG DHCP does the MAC->IP association when it hands out the DHCP lease (only if XG is DHCP server)

    Also is there an ETA on this feature?

    Thanks

    James

Children