Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Portal Access and Active Directory Integration- Authenticated Users Only Access?

Good Afternoon everyone,

Been working with the new XG's over the past couple of months and have an (what I hope is an easy/minor) issue with Portal and VPN access w/AD integration.  Wondering if I could get a little additional help.

Scenario:

Basic Server 2012 R2 Std. environment running AD

XG115 running ver 16.x

Have a new test environment we setup.  We have a specific set of users that we want to have VPN access to only.  Additionally those users will be able to login via the portal to access and download the VPN client software.

 

Problem:

Our problem is limiting what users have access.  My understanding after speaking initially with Sophos support is that we can narrow down who has access to these sections my narrowing down the Search Queries section.

We setup an OU called Security Groups, and inside that OU we created a security group called VPN of which we assign specific members to.

My intention was to set cn=VPN,ou=Security Groups,dc=testdomain,dc=local in the search query.  This yeilded no results however.  Not able to login any user of this object

However, if I move the user to the Security Groups OU and adjust the query to ou=Security Groups,dc=testdomain,dc=local, I'm able to authenticate and access without any problems.

Can we not specify a CN with the XG's?  Am I possibly entering this incorrectly?  This is possible on the UTM side of things, so I would assume the same features would still exist on the XG

It would make more sense to us and be easier to manage if we could specify a CN as opposed to having to drop the user in a particular OU

 

Thoughts?  Advice?  I do have a ticket open with Sophos on this, but it sometimes take days for them to respond and I see that sometimes faster responses come from the community. [:D]



This thread was automatically locked due to age.
Parents
  • Chad,

    The power of utm 9 is granularity! XG does not allow this on some feature like user portal or device access, binding...

    For you question, I would like that user portal works like utm 9 where it is possible to specify users/groups.

    This is my point of view.

  • Thanks for the response Luk,

    So to confirm, this isn't available in XG?

    Might this be something that has already been requsted in future releases?  Not sure where to look for that.

    I thought XG was supposed to be the step up from UTM?  Is this not the case?  Should I be sticking with UTM instead?

    Perhaps I misread when initially going the XG route.  I've easily deployed 20 of these in the past month or two thinking it was going to be taking the place of UTM.  Error on my end possibly.

  • Chad,

    You can have a look at ideas.sophos.com and check XG section to see if the feature request already exists. If it does not, create it and create a new thread here with the link so we everyone can see your thread and vote it.

    If for you this is a needed feature, stay on utm 9.

    Regards

  • Thank you again Luk for the info.  Now to move back to the wonderful world of UTM, as this is a feature set we use often.  From what I see however, it looks like I just wasted money on the XG's as we can't load them up with UTM 9?  I can only jump back and forth on the SG boxes?  Any confirmation on this?

  • Chad, I always advise to test XG or every new system before the purchase. XG is still missing some basic features and we have to wait more time. You can contact your Sophos Sales representative and check if they can help to move back or have a refund. Community is used for technical aspects. Regards
Reply
  • Chad, I always advise to test XG or every new system before the purchase. XG is still missing some basic features and we have to wait more time. You can contact your Sophos Sales representative and check if they can help to move back or have a refund. Community is used for technical aspects. Regards
Children
No Data