Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

STAS problem with user authentication on XG v16

Hi,

I mount a VirtualLab with VM's with XG v16 on my workstation 3 VM's UTM, Windows 7 Pro 64bit and Windows Server 2008 R2 64bit...

  1. XG v16 with two interfaces LAN VMnet5 172.16.16.16 WAN VMnet2 (NAT) DHCP
  2. Windows 7 Workstatin LAN VMnet5 gets DHCP from my Domain Controller 172.16.16.20
  3. Windows Server 2008 R2 64bit LAN VMnet5 roles (Domain Controller, DNS & DHCP) 172.16.16.3

I install the new STAS 2.2.0 in my Domain Controller the Complete suite (Collector and Agent).

  • NetBios: integratec
  • FQDN: integratec.local
  • User: Administrator
  • Collector Sophos HW: 172.16.16.16
  • Agent: 172.16.16.0/24



This thread was automatically locked due to age.
Parents Reply Children
  • irvin,

    GPO to audit account logons event was missing on the defaul domain controller policy (enable it even on default domain controller policy is recommende).

    Also make sure to reboot both DC and then your Windows 7. If live users counter is not incrementing, reboot the XG.

    Regards,

  • Hi, lferrara

    This was very help full.. I will upgrade my appliance in production tomorrow and i will this step.

    1 - Enable Audit on my GPO the Account event logon & event logon (Success / Failure) in both Default Domain Controllers Policy & Default Domain Policy

    2 - Enable Audit on my local security policy for both Account event logon & event logon (Success / Failure)

    3 - Start the STAS collector with the default time of Enable User Inactivity and put the collector IP server and port

    4 - Configure the server sync with Domain Controller, import the group & put domain controller services authentication on first of the list

    5 - Configure the STAS on my server (Agent, Collector, FQDN & Netbios)

     

    With this steps is working good, can you check please?

    Thanks a lot for your time

    Best regard

  • As we did together using remote tool, your list is complete.

    You welcome!