Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Add an Active Directory Server on Sophos XGS

Hi support,

I have a few questions on configure Active Directory authentication on my XGS.

I have followed the guide here:

Configure Active Directory authentication - Sophos Firewall

When I open the VPN portal, I cannot login using my AD user account?

If I add a new user in the AD, does it mean I have to import on the firewall all the time in order to use the VPN?

Isn't it setting the Primary authentication method to my_AD_Server is suppose to be able to authenticate with my AD already?



This thread was automatically locked due to age.
Parents Reply
  • Thanks Bharat J, good news, I managed to get AD user to login to portal.

    The problem now I face is that is that the AD user is not able to ping the server when I log in to VPN. While the user created in the firewall can access and connect to server and ping any computers on the network.

    Is there anything I am missing?

Children
  • Hi TobLai 

    Please make sure you have LAN-VPN and VPN-LAN firewall rules and keep the same firewall rules on TOP to troubleshoot the issue if rules are already present. 

    Please go to System -->Administration --->Device access and enable Ping on VPN and LAN Zone. Also, make sure you have added AD Server or network you want to allow under Permitted network resources (IPv4) as per the snapshot : 

    Thanks and Regards

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • I only have VPN to LAN firewall rules. Is that sufficient?

  • Hey ,

    If you only want the VPN users to access the local LAN resources then it's fine. But if you want the LAN users or client machine to access resources over the VPN then you may want to create a LAN to VPN rule !! 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.