Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RADIUS SSO from WAN zone

Hi there,

I'm trying to get RADIUS SSO working within our organisation for wifi users to be authenticated on the internal and external firewalls. For the external firewall, this is quite straightforward, as the RADIUS accounting packets are generated on the LAN side. However, for the internal firewall at each site, the RADIUS servers are hosted centrally and thus communicate through on the WAN interface. System access won't let me tick RADIUS SSO on the WAN zone - presumably because this is normally Internet facing, but in our context it actually faces our central network and there is another firewall before hitting the Internet.

I've tried configuring a new LAN based zone instead of using the WAN, but then the firewall's own traffic does not get routed anywhere without creating a static route, but then I can't have a failover cellular connection.

I'm really hoping to get a solution that can work for us - it will allow me to deploy Sophos devices to each of our 31 sites.

Thanks,

Phil



This thread was automatically locked due to age.
Parents
  • Hello Phil,

    Thank you for contacting the Sophos Community.

    For this type of question/special setup, I would recommend you to reach out to your Sales Engineer, or Professional Services, so they can work with you in the implementation of what you’re trying to achieve.

    Let me know if you know who your Account Manager, if not send me a PM with your info and I loop your Account Manager.

    Regards,

Reply
  • Hello Phil,

    Thank you for contacting the Sophos Community.

    For this type of question/special setup, I would recommend you to reach out to your Sales Engineer, or Professional Services, so they can work with you in the implementation of what you’re trying to achieve.

    Let me know if you know who your Account Manager, if not send me a PM with your info and I loop your Account Manager.

    Regards,

Children
No Data