Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

STAS in bridge mode

Hello everybody,

I configured a Sophos XG210 in bridge mode. Right now, I’m trying to configure the Single Sign On using STAS. I’m quite familiar with STAS implementation with over 10 clients configured successfully, but this installation is the first in bridge mode and STAS.

I have:

- Created the Auth Server.
- Imported Groups.
- Configured Auth Services.
- Configured Client Authentication in Device Access.
- Installed and configured STAS in the domain controller.
- Configure local security policy in domain controller.
- Configure system auth cta console commands.

following the KB:

https://community.sophos.com/kb/en-US/123154

https://community.sophos.com/kb/en-us/123155

https://community.sophos.com/kb/en-us/123158

I've already tested successfully, on STAS in the domain controller, if it can reach Sophos Firewall

Am I missing an additional step with the bridge mode?

Thanks in advance for your help.

Regards,

Jose



This thread was automatically locked due to age.
Parents
  • Hi Jose,

    There is no configuration change to configure STAS with XG in bridge mode. Hence, re-verify the configuration.

    Thanks

  • Hi Sachin,

    you're right. I just disable and re-enable the auth cta in Sophos Console, and everything started up succesfully.

    To disable, go to sophos console, option 4:

    system auth cta disable.

    To re-enable and add a collector:

    system auth cta enable

    system auth cta collector add collector-ip [Colector IP] collector-port [Collector port - default 6677] create-new-collector-group

    Regards,

    Jose

Reply
  • Hi Sachin,

    you're right. I just disable and re-enable the auth cta in Sophos Console, and everything started up succesfully.

    To disable, go to sophos console, option 4:

    system auth cta disable.

    To re-enable and add a collector:

    system auth cta enable

    system auth cta collector add collector-ip [Colector IP] collector-port [Collector port - default 6677] create-new-collector-group

    Regards,

    Jose

Children
No Data