This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Remote STAS in bridge mode

Remote STAS in bridge mode

Hello guys.

I'm approving an environment where we have sophos in bridge mode.

The following scenario being evaluated.

Office:

router <-> sophos fw(l2) <-> switches

Inside this office we have an AD with STAS, running and working.

Branch:
router <-> sophos fw(l2) <-> switches

This branch does not have an AD, so authentication will take place through the STAS installed in the office's AD.

What is the problem:

As it is configured in bridge mode the incoming connection hits the WAN zone and is denied by local_acl.

Unfortunately in the "Device Access" settings there is no way to allow it in the WAN zone. How could I release?



This thread was automatically locked due to age.

Top Replies

  • Hi Gib GoDesk 

    STAS does not support from WAN zone, and as per your scenario, Sophos is configured in bridge mode which has the below the limitation:  1)   Virtual Private Network (VPN) 2)   Multi-Link Manager (MLM) 3) DMZ Zones where the shared link might not help as not enough information how Sophos exactly deployed only bridge mode or mixed mode to check go to  Configure -->Network --->Interfaces configured currently. 

    Further, it would be great if you contact  Sales Engineers or Partners to confirm that you meet your requirement with mixed mode and follow the link I have shared.

    Thanks and Regards 

    Jump to answer