This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG detect wrong user group

Hi everyone,

I'm using SFOS 17.5.7 MR7. I having an issue about user group.
I have Active directory server as a authentication server. I have some group for user where i can apply policy for each. 
This was running fine. But recently I notice some users are associated to wrong group.
For example I'm an IT, I supposed to be in IT group, but Sophos XG put me in Staff group, which is a default group I set in Authentication server list. 
And the most weirdest thing is that although XG put me in Staff group, it applies the IT policy for me. In IT policy, I only put IT group in Identity. 

I checked all the configuration following the KB https://community.sophos.com/kb/en-us/123158 and https://community.sophos.com/kb/en-us/123161 and I'm quite sure I did right.

But I have no idea what's wrong with my XG. Could you please advice?



This thread was automatically locked due to age.
Parents Reply
  • As previously said, this is not a bug. It is a feature. 

    XG reads all groups (created on XG) from the AD, stores this information in the Backend and uses this for Firewall and Proxy.

    So called, if you have a User in IT and User for example, and you create a firewall Rule with Group IT, this Firewall Rule will be used. 

    Firewall Rule uses "first match". 

    There is a Bug in Firewall Policy Tester, which does not deflect this behavior. The Firewall Policy Tester only uses the Primary Group - So this will give you a wrong output.

    But the firewall Rule will work properly. 

     

    The Question is, what do you want to archive? Such Setups with multiple groups in it can be very complex. 

Children