Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

STAS and User logging not working as expected

Hi all,

Hoping someone can point me in the right direction.

I have enabled STAS on our Sophos XG.
I can see user showing on the STAS Agent on the server.

I have also added the server to the XG on the Auth List and connections pass without issue.
I have imported the Group "Domain Users" into the XG from the Connected Server.

Now my issue is when I set my Firewall rule to "match known Users" and select Domain users as the group no traffic flows via this rule, however, if I set the group to "ANY" traffic flows through it as expected.

How can I set this rule for domain users only?



This thread was automatically locked due to age.
Parents Reply Children
  • Set to domain users

    Ethernet header
    Source MAC address:74:8*******
    Destination MAC address: 7c:5*******
    Ethernet type IPv4 (0x800)

    IPv4 Header
    Source IP address:10.2******
    Destination IP address:91.1******
    protocol: TCP
    Header:20 Bytes
    Type of service: 0
    Total length: 40 Bytes
    Identification:38899
    Fragment offset:16384
    Time to live: 128
    Checksum: 64579

    TCP Header:
    Source port: 57568
    Destination port: 443
    Flags: ACK
    Sequence number: 249620782
    Acknowledgement number: 1008359775
    Window: 1026
    Checksum: 54549

    Set to ANY

    Ethernet header
    Source MAC address:74:8*******
    Destination MAC address: 7c:5*******
    Ethernet type IPv4 (0x800)

    IPv4 Header
    Source IP address:10.2*****
    Destination IP address:91.1*****
    protocol: TCP
    Header:20 Bytes
    Type of service: 0
    Total length: 40 Bytes
    Identification:39059
    Fragment offset:16384
    Time to live: 128
    Checksum: 64419

    TCP Header:
    Source port: 57568
    Destination port: 443
    Flags: ACK
    Sequence number: 249620782
    Acknowledgement number: 1008940507
    Window: 1026
    Checksum: 63632

  • No, just share the screenshot of the GUI packet capture, do you any traffic going in and out from the interface and which FW rule id or NAT id it detects ? 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Interestingly the Rule IDs show as 0 for both

    Any

    Domain users

    However, they should be hitting FW Rule 15/16.

  • The AD server and the local users are both in the same zone right ?
    And all the domain users are present under the group Doman users, right ?
    if authentication zone LAN is in the picture, can you ensure the option "client authentication" is enabled under the administration > device access  

    Here is also the best practice guide you may want to refer - Sophos Firewall: Best practice for STAS

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Hi,

    Yep the server and users are in the same Zone.
    Yep users are part of the domain users group

    and yep, Client Auth is enabled for LAN under Device Access

    I have had a quick look at that guide and I have done all that is listed.
    Strange one, will continue to have a play.

  • I have reached out to Support as everything is the same as that guide.

    Cheers