Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Authentication behavior malfunctioning

Hi All,

I will consider the problem with authentication mechanism using STAS. we are running Sophos XG Firewall in Proxy Mode.

The problem scenario is:

I am using internet with my authentication which is perfectly fine.  lets say, I want to access another windows computer's hard drive but I have no rights on that system. other computer will prompt me for network authentication , and I gave it some authentication which has rights onto that computer e.g. domain admin's account.

now when I will resume my internet browsing. the appliance rejects my request because it says my user is "domain admin's account" and it is blocked because domain admin's account have no internet rights.

there is another problem I can relate to this is: when I take RDP of a computer, specially of a server or terminal server with my credentials. web browsing seems to work fine. but after some time idle, web browser shows block request with the user which is physically logged onto that particular server.

in case of a terminal server, the block request page shows random username of all other users which have no internet browsing rights in Sophos XG.

something is fishy in this whole scenario , and root cause might be a single one. but I cant seems to find it.

kindly suggest any solution if this scenario is familiar.

Regards,

Faheem Sarwar



This thread was automatically locked due to age.
  • Hi Farheem,

    Is the Administrator account configured in the exclusion list on STAS?

    Next, if you are using a terminal server are you also using SATC for authentication? In that case, I would request you to start a new thread, we have an unwritten rule about one query per thread.

    Also, I suggest you an upgrade to our latest firmware and monitor the issue. Post accessserver.log when you face such behavior.

    Thanks