Hardware: Sophos XG 125
Firmware: XG125 (SFOS 15.01.0 MR-2)
SAA version: 1.2
I am already in contact with support for this one, but reposting here in case some from user community may have solved it already. Thanks in advance :)
The problem:
SAA disconnects every 8-10 minutes requiring user to reconnect manually.
Background:
- We use Azure Active Directory (Office 365). As we don’t have an in-house Active Directory, SSO with AD cannot be used.
- We don’t want the end user to login frequently to just access internet, so Captive Portal Authentication cannot be used.
- As a result, only Sophos Authentication Agent (SAA) is the ONLY way identity can be implemented here.
On to SAA now:
- It is perfectly fine if SAA goes offline if the user is inactive (icon turning gray) for simple efficiency reasons.
- But, SAA NEEDs to come back online AUTOMATICALLY with the saved password whenever the internet connection is required. THIS IS NOT HAPPENING. The user have to find the system tray icon (often Windows hides it). Then right click on “Set Credentials” to see the SAA user interface and click OK to come back online. This Leads to a lot loss of productivity and heartburn for end users.
On to the last debugging session with support team:
- We have monitored the SAA on a few machines and it is continues to disconnect. At this point of time, the ICMP ping to Sophos Gateway works normally on the end machine.
- The client machine does not have any local firewall (expect Windows default) or any specific antivirus (except Windows Defender). Both these products DO NOT obstruct the traffic between Sophos Gateway and local machine or SAA. If it would have, how does SAA work for first 8 to 10 minutes?
- We have checked any additional hardware in between. There is only one switch (Netgear GS724Tv4). It is not configured to inspect any traffic or for any other traffic shaping. Also, if this switch would have been a problem for breaking the PING/PONG of SAA with Sophos Gateway, there is no reason why it won’t do so in the first few minutes? Why there is even connectivity if this switch is dropping this basic PING/PONG?
Conclusion:
The simple questions that need to be answered on this issue are
- Why SAA does not reconnect automatically?
- Why SAA goes offline every 8-10 minutes even after the Global Time-out settings suggest different behaviour?
- Why SAA works for first 8-10 minutes?
- Why no one including, in-between switches, local firewall or local anti-virus do not intervene for first 8-10 minutes when SAA works as expected?
- Why SAA works after manual re-connect?
Apologies for any agitated tone in the post, it is not directed towards community :)
This thread was automatically locked due to age.