Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Client Authentication Agent disconnect randomly.

Hi,

We have a XG 135 firmware version XG135 (SFOS 18.5.2 MR-2-Build380) running in our office. We have a mix of clients using Windows 7, Windows 10,Windows 11


We are running client authentication agent on each system to login into the firewall. All the values that could disconnect a system like Inactivity settings are already increased. 

We have observe the logs and it shows the log in/log out of users. We are facing this Problem with Latest Version of Windows 10 and Windows 11 Users only. In Every 10-15 Minutes user get log out itself. 



This thread was automatically locked due to age.
  • Hi : In order to narrow down the issue you may capture the below logs and from that, you may identify the possible causes of this disconnection or logout.

    You may apply the authentication service ( access_server) in debug mode with the below command:

    #service access_server:debug -ds nosync

    #service -S | grep access_server

    The same command will revert the service from debug to normal mode as well.

    You may open 3 Putty sessions of XG and you may start saving the logs of those putty sessions in a text file.

    1) In Putty 1, start the access_server debug tracking via the below command.

    #tail -f /log/access_server.log/access_server

    2)In Putty 2, start the TCPDUMP on Port TCP 9922 which is getting used by CAA App with XG to have keep-alive connectivity.

    console> tcpdump 'port 9922

    3)In Putty 3, start the drop packet capture on Port TCP 9922 to see any keep-alive packets getting dropped or not.

    console> drop-packet-capture 'port 9922

    Once the issue get re-produced for any 1 or 2 users you may stop the above putty session log and you may check the details to identify the issue.

    It may possible keep alive from system to XG not reaching due to which CAA connection getting lost or any other possible reasons as well based on logs validation.

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?