This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SFOS 16.05.6 MR-6 Broken STAS?

Hi All,

 

We have an XG 230 that I upgraded the firmware on. Since then users are getting the authentication pop up from the XG where others are fine.

Rebooting their PC fixes some so it might lead to a fresh login event fixing it. The Firewall shows them logging in but then logging out and then I get a Authentication fail.

Seems STAS is working for many but randomly fails others since the Firmware update.

I run two DCs with STAS enabled (Latest version of STAS) and I can see live users active yet others not. The inactivity time outs are set high so they would need to walk away for a few hours to be timed out.

EDIT: I disabled the Inactivity time out but still have the issue.

  

The logs just show NTML Client failed to Authenticate

Anyone else having this issue?

 

 

Edit: I can see a few others having the same since the update so I will roll back my Firmware for now until a fix is released.



This thread was automatically locked due to age.
Parents
  • Very strange, STAS is working fine for me on MR6.  I'll be following this thread very closely though. 

  • Bill Roland said:

    Very strange, STAS is working fine for me on MR6.  I'll be following this thread very closely though. 

     

     

    Out of curiosity what OS are your collectors installed on?

  • I have one on Server 2008 R2 and one on Server 2016

    Sophos XG 450 (SFOS 18.5.1 MR-1)

    Sophos R.E.D 50 x 2

    Always configuring new stuff.....

  • Windows Server 2012R2 for me.

  • I did have an older version of the STAS Collector on both DC's but updated both to the latest 2.2.1.0 before I rolled back thinking this might be the issue.

    Sophos XG 450 (SFOS 18.5.1 MR-1)

    Sophos R.E.D 50 x 2

    Always configuring new stuff.....

  • Ian Melton said:

    I have one on Server 2008 R2 and one on Server 2016

     

     

    and which one is getting hit the most? I have two collectors also but it seems only one gets hit with queries

  • Yeah mine is similar.

    If I open STAS Collector on my Server 2008 R2 box I can only see two live users - The XG reports 162 live users right now.

    The server 16 STAS has no live users

    Sophos XG 450 (SFOS 18.5.1 MR-1)

    Sophos R.E.D 50 x 2

    Always configuring new stuff.....

  • Ian Melton said:

    Yeah mine is similar.

    If I open STAS Collector on my Server 2008 R2 box I can only see two live users - The XG reports 162 live users right now.

    The server 16 STAS has no live users

     

     

    I see lots of errors in the Event Log regarding unable to connect to host to run WMI probes. Since I've altered the security I see less events but at lease the ones that are there are genuine connection refusals. Ive had to add the STAS user account to DCOM group in a GPO to get this thing to stabilise. 

    No doubt as a result of MS updates tightening security from ransomware exploits, this has all gone to hell in a hand basket. Ironically STAS auth utilises the same methods the worms use to infiltrate networks.

  • I see plenty of these:

     

    wrkstpoll_workerthread_wmi: couldnt connected to WMI Namespace '\\192.168.8.94\root\cimv2': 0x800706ba

     

    But users are still getting access via the Proxy so not sure its actually effecting anything.

    Not a fan of STAS - I would rather it be like the SG and connect it to AD directly

    Sophos XG 450 (SFOS 18.5.1 MR-1)

    Sophos R.E.D 50 x 2

    Always configuring new stuff.....

Reply
  • I see plenty of these:

     

    wrkstpoll_workerthread_wmi: couldnt connected to WMI Namespace '\\192.168.8.94\root\cimv2': 0x800706ba

     

    But users are still getting access via the Proxy so not sure its actually effecting anything.

    Not a fan of STAS - I would rather it be like the SG and connect it to AD directly

    Sophos XG 450 (SFOS 18.5.1 MR-1)

    Sophos R.E.D 50 x 2

    Always configuring new stuff.....

Children