Please bear with me, I am a 1-man IT band, and am NOT a "Firewall" guy. :-)
Background:
Simple Network:
- 2 Active Directory Domain controller Servers (for redundancy) w/ STAS Suite loaded on BOTH controllers.
- 1 XG Sophos Firewall XG 230
I am in the works setting up a new Sophos XG 230 for our business, and decided that "Clientless SSO Authentication w/ AD" sounded the best? (I THINK)?
I have it up and running, BUT was dealing with some issues with a test workstation being disconnected within minutes of logging on, even though I had "Dead Entry Timeout" selected on the STAS Suite for 2 hours (for testing). Within minutes of logging on, (and showing up under "Live Connections" the workstation would suddenly drop off the list. If I "logoff" or even "Lock" the workstation and log back in... it works again for a few minutes.
After working with support for some time, I noticed if I set "Dead entry timeout" on the AD Domain Controllers STAS Suite to 0 (disabled) this not longer happened and the user would stay connected indefinitely. Previously had it set for 2 hours (just for testing).
BUT... I noticed in the Sophos Article: "Sophos Firewall: Clientless Single Sign-On in a Active Directory Domain Controller Environment" it states:
Note:
- Ensure Logoff Detection and Dead Entry Timeout are not simultaneously disabled because users will remain live in the STAS DB. (which is what I just did in order to rectify my problem of my test workstation getting dropped off every few minutes).
Question to you guys MUCH smarter than I: What is the most FOOL PROOF, dependable, way to setup SSO w/ AD authentication (As far as logging off workstations that sit idle for an extended period)?
- Logoff Detection? (On STAS Suite on AD Domain Controllers)?
- Dead entry timeout? (on STAS Suite on AD Domain Controllers)?
- " Enable User Inactivity"? (on Sophos XG firewall)?
- Which one? or Combination?
Again, my only concern is that I am not missing some Security hole, or Performance issue by leaving users connected indefinitely on either the XG firewall or STAS Suite (DC's).
Long story short, I am looking to see what you guys with MUCH more KNOWLEDGE than I recommend for SSO w/ AD integration settings. (especially pertaining to Logoff due to idle time).
THANKS!
This thread was automatically locked due to age.