This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

STAS Collectors - Best Practice?

Hey guys,

Does anyone have / know what Sophos XG best practice is for Collector Groups?

I currently run 3 DCs and I have each on its own Collector group:

 

STAS v2.5.0.0 on each.

Should I have all 3 inside one Collector Group?

What is the reasoning for a Yes or No - I can see some recommend it and an "XG Expert" who assisted with this set up said it was better to have multiple groups but didn't elaborate why.

My issue is random PC's not Authenticating with STAS - random as in 5 / 250 and I cannot see why when all Tests and AD / STAS / WMI etc work fine

 

What do you do?



This thread was automatically locked due to age.
Parents
  • Hi  

    STAS fault tolerance

    You can install STAS collectors on multiple AD servers for redundancy purpose, if the primary collector goes down, Sophos XG Firewall gathers the information from one of the other backup collectors. Sophos XG Firewall allows creating groups of collectors for fault tolerance. A maximum of 5 collectors can be added to a single collector group. When multiple STAS collectors are added to a single collector group, one of these will act as a primary, while the others will be reserved for backup. Collector preference is processed in order from top to bottom.

    In the example below,  the active collector for testlab.com (Collector Group 1) would be 192.168.1.10, while 192.168.1.185 would serve as a backup should the active collector go offline. Additional domains or sub-domains should be added as an additional collector group. For example, the controller for the subdomain remote.testlab.com, 192.168.2.20 would be added as a standalone collector for Collector Group 2.


    Reference community thread:

    https://community.sophos.com/products/xg-firewall/f/authentication/83938/multiple-stas-collectors

    Hope this helps!

  • Keyur said:
    would serve as a backup should the active collector go offline

     

    So in my case I am probably better to create 1 collector group and add my 3 DCs to it so I get full failover.

Reply Children