Firewall always logout users randomly
This thread was automatically locked due to age.
Couldn't agree more!!!
Using 2 x XG230s...
1.VPN continually drops out.
2. Captive Portal only displays an IP address so cannot use publicly signed certificate.
3. One of the XGs needed a reboot, so decided to drop it's captive portal and start letting any wireless device on the network.
4. STAS does NOT work full stop.
Hi,
Can you be more specific about your issues?
VPN should be stabil by now.
You can use the hostname instead of IP address: https://community.sophos.com/kb/en-us/132058
I cannot understand point 3.
And as far as i can tell, STAS works fine in most of my setups for now. And - if you do not want to go with STAS, you could try out the SSO client. https://community.sophos.com/kb/en-us/123159
Maybe FloSupport can follow up this query?
Hi,
Can you be more specific about your issues?
VPN should be stabil by now.
You can use the hostname instead of IP address: https://community.sophos.com/kb/en-us/132058
I cannot understand point 3.
And as far as i can tell, STAS works fine in most of my setups for now. And - if you do not want to go with STAS, you could try out the SSO client. https://community.sophos.com/kb/en-us/123159
Maybe FloSupport can follow up this query?
Many thanks for the quick response MBP,
1.The VPN between the two XGs drops out randomly, perhaps once a fortnight, and it never comes back up after a reboot. I have to go in to VPN (both icons are green but no VPN exists) and click 'Disconnect' then 'Connect' in the VPN window.
Any advice on the IPSEC settings which should be most stable would be greatly appriecated?
2. Huge thanks for this: https://community.sophos.com/kb/en-us/132058 I had not seen its release in July.
Last time I spoke to Sophos Support they said the Captive Portal would only display an IP address and therefore a CA signed certificate would always give a security error. I shall the set the value of the proxy_url_use_hostname to on and purchase a new certificate.
3. STAS users keep disconnecting and have done since I purchased the XGs. I've had a support ticket open since Feb 2018.
All tests in STAS (WMI, Reg, Agent, Collector) show as successful. Live users appear in STAS and then randomly drop off, anywhere between 4min-4hrs. Recently I added another domain controller running the Sophos agent. Any clients authenticated against that DC, in 'Show Live Users' display the XG's ip address?! Then, suddenly appear again with the correct ip address and then drop off.
Again, any advise would be greatly appreciated.
Cheers
Could you please open a thread for each topic at their own? Would like to refer to each topic individual.
Thanks!
Have split them into 2 threads, MBP.
Your suggestion for the https certificate looks to have solved the public signing issue.
Many thanks again