I just installed a new SG310 in one of our datacenters. We have multiple locations, and several Sophos appliances running different versions. As the title suggests on the newest appliance I've installed I actually pulled out an appliance running UTM 9.5 and put in a new one running XG 17. On version 9.5 STAS worked. Now on 17 it does not. I've looked at it with support and they seem to be stumped. Running the tests from the STAS client it says it's successful, and the client is showing "live users" so that portion seems to be working. But on the actual firewall none of the users are populating. AD authentication does work. If I direct a user to the user portal they can log in there and their user does show up after that. Also, the authentication portion of the logs is filled with errors saying "User jdoe failed to login to Firewall through AD,AD,Local authentication mechanism from x.x.x.x because of wrong credentials" (username and ip have been removed). These login failures all appear to be caused by an issue with SSO because there isn't anything on the firewall itself that our users log into, we don't really use or advertise the user portal unless it's needed for a specific reason. Anyone seen this before, and/or have any recommendations on what to check. I've set up quite a few of these appliances before and have never had trouble getting this working.
This thread was automatically locked due to age.