Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Authentication behavior STAS / CTA

Hi all,

In my network I have some users that logon into Windows domain. Some of that users need to connect also to internal Terminal Server (RDS).

I configure XG (16.05.3) to authenticate with AD, import groups from AD and enable auth services (Firewall Auth Method).

Into Auth -> STAS: enable Sophos Transparent Authentication Suite, disable Enable User Inactivity, and specify collector (DC).

In terminal Server I install CTA and configure it (ip of firewall)

I configure Local GPO into Domain Controller to intercept logon events and then install STAS on Domain Controller when I specify IP of terminal server into Exclude IP in STAS.

I configuire one GPO to permit "Remote Administration" and ICMP on Client computers -> ( to permit WMI or ping logoff detection)

The users logon into their PC with domain account, and I see it into "Current Activities" -> Live Users...   (Client Type = SSO) OK -> client can browse internet.

When the user next logon in Terminal Server -> I see it into "Current Activities" -> Live Users...   (Client Type = Thin Client) but I can't see the previous SSO.

In fact the user can browse from Terminal Server but he can't browse from PC.

I expect two users (one of type SSO and one of type Thin Client).

What's wrong?

P.S Note that if I try to filter "Client Type" = SSO into "Current Activities" -> Live Users... show me nothing... (but SSO client exists in list) -> bug???



This thread was automatically locked due to age.
Parents Reply Children
  • Ciao Luk,

    Firstly

    I'm migrating from Cyberoam to Sophos... first in main site (2x CR50iNG in HA) then in remote site (2xCR25iNG in HA).

    Terminal Server IP is present in main site and it's alredy present inside Exclusion List of STAS installed on DC.

    I have another DC in remote site .. I need install STAS on remote DC?

    Normally user connect to DC in the local site... I've correctly setup AD Site & Service with different subnets (one for "remote office" subnet 10.2.0.0/16 and one for "main site" subnet 10.1.0.0/16).

    In remote site it's present CTAS on remote DC (Cyberoam implementation of STAS).