Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Clientless SSO STAS logoff detection vs dead entry timeout clarification needed

Please bear with me, I am a 1-man IT band, and am NOT a "Firewall" guy. :-)

Background:

Simple Network:

  • 2 Active Directory Domain controller Servers (for redundancy) w/ STAS Suite loaded on BOTH controllers.
  • 1 XG Sophos Firewall XG 230

 

I am in the works setting up a new Sophos XG 230 for our business, and decided that "Clientless SSO Authentication w/ AD" sounded the best? (I THINK)?

I have it up and running, BUT was dealing with some issues with a test workstation being disconnected within minutes of logging on, even though I had "Dead Entry Timeout" selected on the STAS Suite for 2 hours (for testing).  Within minutes of logging on, (and showing up under "Live Connections" the workstation would suddenly drop off the list.  If I "logoff" or even "Lock" the workstation and log back in... it works again for a few minutes.


After working with support for some time, I noticed if I set "Dead entry timeout" on the AD Domain Controllers STAS Suite to 0 (disabled) this not longer happened and the user would stay connected indefinitely.  Previously had it set for 2 hours (just for testing).

BUT... I noticed in the Sophos Article: "Sophos Firewall: Clientless Single Sign-On in a Active Directory Domain Controller Environment" it states:

Note:

  • Ensure Logoff Detection and Dead Entry Timeout are not simultaneously disabled because users will remain live in the STAS DB.  (which is what I just did in order to rectify my problem of my test workstation getting dropped off every few minutes).

 

Question to you guys MUCH smarter than I:  What is the most FOOL PROOF, dependable, way to setup SSO w/ AD authentication (As far as logging off workstations that sit idle for an extended period)?

  •   Logoff Detection? (On STAS Suite on AD Domain Controllers)?
  •   Dead entry timeout? (on STAS Suite on AD Domain Controllers)?
  • "  Enable User Inactivity"?  (on Sophos XG firewall)?

- Which one?  or Combination?

Again, my only concern is that I am not missing some Security hole, or Performance issue by leaving users connected indefinitely on either the XG firewall or STAS Suite (DC's).

Long story short, I am looking to see what you guys with MUCH more KNOWLEDGE than I recommend for SSO w/ AD integration settings. (especially pertaining to Logoff due to idle time).

THANKS!

 



This thread was automatically locked due to age.
Parents
  • Hi Jarrod,

    User logoff detection works in conjunction with the Windows WMI queries to detect a logoff entry. Read the KBA here for further information. Alongside, ‘Dead entry timeout’ is independent of whether the Logoff Detection is enabled or not. Using Dead Entry Timeout in STAS, an administrator can configure the time period (in hours) after which a user is to be logged out from the XG. After user login, on completion of the specified time period, the user is automatically logged out. 

    One of the most interesting, User inactivity timeout is necessary for Single Sign On implementation to get the accurate reporting about a user's activity. Users at their workplace do not shut down their system at the end of their shifts. If User is configured for Single sign on, whenever User logs on to Windows, he/she is automatically logged to the appliance. So, in XG Live User Page, users will remain logged in till the next time he/she logs into the Windows Domain. This would result in showing the User on the Live UserPage for many days without any logoff. To avoid such situation ‘Inactivity Time’ parameter for STAS settings must be configured.

    Hope that helps.

Reply
  • Hi Jarrod,

    User logoff detection works in conjunction with the Windows WMI queries to detect a logoff entry. Read the KBA here for further information. Alongside, ‘Dead entry timeout’ is independent of whether the Logoff Detection is enabled or not. Using Dead Entry Timeout in STAS, an administrator can configure the time period (in hours) after which a user is to be logged out from the XG. After user login, on completion of the specified time period, the user is automatically logged out. 

    One of the most interesting, User inactivity timeout is necessary for Single Sign On implementation to get the accurate reporting about a user's activity. Users at their workplace do not shut down their system at the end of their shifts. If User is configured for Single sign on, whenever User logs on to Windows, he/she is automatically logged to the appliance. So, in XG Live User Page, users will remain logged in till the next time he/she logs into the Windows Domain. This would result in showing the User on the Live UserPage for many days without any logoff. To avoid such situation ‘Inactivity Time’ parameter for STAS settings must be configured.

    Hope that helps.

Children
  • Thank you for the reply...

    Here is what I was "THINKING" would work... PLEASE let me know if you think this is a good option or if there is a better solution/approach!

    Implementation Ideal:

    • Enable:  "Dead entry timeout" set for 9 hours (this way the user should stay logged in all day, but will be eventually logged off after work hours  (NOTE: Should this be set on BOTH DC's or just the primary)?
    • Enable: "Enable User Inactivity" on Sophos XG Firewall. 

    Question:

    • Do these 2 settings work well together?  Or should I use a different combination?

    NOTE: whatever settings I use, I am trying to avoid adding exceptions or software to the workstations (just do to limited time, and creating more possible issues/security holes).  Just want a reliable solution that is stable and easy to implement.

     

    Thanks again!

     

  • Hi Jarrod,

    I think is a good configuration to go with but, the perfect one will only come after several permutations; learning the need in your network. This shall give you an inch inside the reporting section alongside, it will also automatically sign out the users after 9 hours. 

    Thanks