Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VPN user in firewall polcies

how can i apply policies based on the VPN users. Remote VPN users login to Sophos connect client. Based on the user logged in access has to be given.

If user1 logs in to sophos connect, he'll be given access to server 1 only.

If user2 logs in to sophos connect, he'll be given access to server 2 only.



This thread was automatically locked due to age.
Parents Reply Children
  • That is odd. Do you have Captive Portal or another authentication enabled for this zone VPN? Because it should list the users. If live users does not have the user with IP mapping in there, that is essentially the issue, why a firewall rule with match user is not working.

    Could you go to the logviewer - authentication and check, if there are authentication succesful and unsuccesful entries are for those VPN users? 

    __________________________________________________________________________________________________________________

  • captive portal was disabled, to check i enabled it. The authentication log is strange, there's both failed and successful logs for a single user login.

  • This should give us an indication: Access Server is actually denying this user because of Time Policy. Check the user and the Access Policy you are using. 

    __________________________________________________________________________________________________________________

  • Woow, that was an incredible observation. The issue is now resolved, I can see username in the logs. User based policy also working now.
    Access time in user properites was denied all time.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?