Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

OTP / 2FA "Sophos SF0" issue with multiple XG Firewalls on Reiner SCT G1

Hi,

we're evaluating hardware Tokens from Reiner SCT, quite commonly used in Germany.

OTP or 2FA is working fine with Sophos XG as long as you only have one Firewall.

Because the QR code is identified as name "Sophos SF0", whatever this means, if you have a second firewall and enable OTP there, scan the new QR Code, it will overwrite the existing "Sophos SF0" dataset without question. You will not be able to login to the first firewall.

Any idea, where the name Sophos SF0 comes from and if you can change that somehow? Maybe on the CLI?

Would be ways better, if this could be the hostname of the firewall instead of that generic SF0 name.



This thread was automatically locked due to age.
Parents Reply
  • Wondering, my Sophos Intercept X app does it correctly. So maybe the vendor of your app does read the wrong value in the QR Code? 

    Because the QR Code rawr format is: otpauth://totp/Email of User ?secret=suer=Sophos%20SFOS&period=30

    I assume, the QR Code Tool only Reads: Sophos SFO 

    It should use the Creds of the UPN in front of the secret. 

Children