Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos xg not creating a domain computer account when adding active directory authentication server. Kerberos sso not working.

I have added Active Directory Domain controller to the servers list under authentication, imported groups, have users from AD, however, kerberos/ntlm doesnt work. I have made sure that SSO is enabled for the LAN interface and that the browser is using the FQDN hostname of the appliance in the proxy setting. What i do notice is that there is no computer account created in AD.



This thread was automatically locked due to age.
Parents
  • Check the Logs about /log/nasm.log 

    It should indicate the join.

    You can delete the entry of nasm and redo the join to generate new logs. 

    Stop the NASM service: service nasm:stop -ds nosync

    Remove file /content/nasm: rm -rf /content/nasm

    Start the NASM service: service nasm:start -ds nosync

    __________________________________________________________________________________________________________________

Reply
  • Check the Logs about /log/nasm.log 

    It should indicate the join.

    You can delete the entry of nasm and redo the join to generate new logs. 

    Stop the NASM service: service nasm:stop -ds nosync

    Remove file /content/nasm: rm -rf /content/nasm

    Start the NASM service: service nasm:start -ds nosync

    __________________________________________________________________________________________________________________

Children
  • That was exactly it, thank you! Is this a case of a configuration file being created and the XG not recreating the domain computer object because the configuration file is present? What is the -ds nosync option mean? I would love to know more of the inner workings. Again, thank you!

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?