This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSO AD User logout continuously

Hi,

i have a xg firewall with AD SSO.

the users logged into the firewall are continuosly logged out after 20 minutes

2016-04-11 08:44:32
Firewall Authentication
SUCCESSFUL
dario.zzzz@xxxx.local
172.16.29.115
CTA
N/A
User dario.zzzz@xxxx.local was logged out of firewall
17703
2016-04-11 08:28:48
Firewall Authentication
SUCCESSFUL
dario.zzzz@xxxx.local
172.16.29.115
CTA
AD
User dario.zzzz@xxxx.local of group Proxy_All logged in successfully to Firewall through AD authentication mechanism from 172.16.29.115
17701


I have followed all the guides but I can not fix it

thanks

Emil



This thread was automatically locked due to age.
Parents
  • I am having a similar issue and know what is causing it but do not know how to fix it. 

     Scenario:

    USER_A logs into COMPUTER_1 and is authenticated properly.

    USER_A then remote desktops to COMPUTER_2 and logs in as USER_B. 

    USER_B is now showing as the authenticated user for COMPUTER_1, even though it should still be USER_A because USER_A is still logged into COMPUTER_1.

    20 minutes later, USER_A is disconnected and has no access to the internet on COMPUTER_1. 

    Under the STAS exclusion list I've added USER_B as a login exclusion and the IP address of COMPUTER_2 as a login/logoff exclusion. 

    This is extremely annoying, as I am constantly using Remote Desktop to connect to another machine with a different username than the username I am presently logged into on my local machine. 

  • Christopher,

    I have this exact same issue, did you get anywhere with it?

    If I remote desktop anywhere as my Admin account, it takes that as a local logon event on my PC and logs my standard user account off the firewall. (Making the internet stop working)

     

    I have put an exclusion in for my admin account on the STAS collector and that has done the trick, However,

    sometimes we log into the RDS Servers as other users (to setup profiles or troubleshoot)... this will also log our standard user off the firewall.

     

    Thanks,

    Matt

  • In addition to adding my administrator username to the Login User Exclusion List, I also added the IP Address of our servers so that when logging in/out of these servers it would be excluded. 

  • Now I have a suggestion from Sophos Support  to switch off an "inactivity detection" in STAS completely AND switch it on in Sophos XG. I´ll post results - if any.

  • Hi All, 

    Could you change the settings as per the snapshot below and check if this would resolve your issue?

  • Tomorrow I check this (I have same problem - logoff).. and I report results.

     

    I want to report that in "Current Activities/Live Users", if I filter by "Client Type" SSO, that filter does not show me anything (SFOS 16.05.4 MR-4)

  • I simply ended with following:

     

    STAS logoff detection simply doesn´t work - sorry for this solution, but we decided not to cope with this problem anymore.

    We tried tens of possible configurations - without success. I appreciate work of Sophos engineers, but ,unfortunately, this part of STAS simply DOESN´T WORK.

     

    We decided to switch on "Inactivity timeout" on Sophos XG firewall. It is suboptimal solution, but (in some way) works.

Reply
  • I simply ended with following:

     

    STAS logoff detection simply doesn´t work - sorry for this solution, but we decided not to cope with this problem anymore.

    We tried tens of possible configurations - without success. I appreciate work of Sophos engineers, but ,unfortunately, this part of STAS simply DOESN´T WORK.

     

    We decided to switch on "Inactivity timeout" on Sophos XG firewall. It is suboptimal solution, but (in some way) works.

Children
No Data