Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RADIUS SSO from WAN zone

Hi there,

I'm trying to get RADIUS SSO working within our organisation for wifi users to be authenticated on the internal and external firewalls. For the external firewall, this is quite straightforward, as the RADIUS accounting packets are generated on the LAN side. However, for the internal firewall at each site, the RADIUS servers are hosted centrally and thus communicate through on the WAN interface. System access won't let me tick RADIUS SSO on the WAN zone - presumably because this is normally Internet facing, but in our context it actually faces our central network and there is another firewall before hitting the Internet.

I've tried configuring a new LAN based zone instead of using the WAN, but then the firewall's own traffic does not get routed anywhere without creating a static route, but then I can't have a failover cellular connection.

I'm really hoping to get a solution that can work for us - it will allow me to deploy Sophos devices to each of our 31 sites.

Thanks,

Phil



This thread was automatically locked due to age.
Parents Reply
  • Hi Ian,

    I didn't really explain it very well.. here's a simplified diagram that shows the basic operation - to keep it simple I've omitted the vlans and switching at each school (the purpose for the routing firewall). Each school connects back to the datacentre (where the servers live) via a private network before hitting the Internet.

Children
No Data