This question appears to have been asked several times over the past few years, but I can't find a definitive answer yet - apologies if it has been answered and I just need a link!
I'm trying to setup a network whereby we can bring our own mobile devices / laptops, but using our work AD credentials we can sign into a dedicated employee wifi network (WPA2 Enterprise) and it uses the same credentials on the WiFi to automatically authenticate the device through the firewall. Effectively once you've connected to the WiFi initially, you never need to enter another security challenge.
I've searched for how to do this using my equipment and Sophos XG so I can get better visibility of connected devices and apply more appropriate web filtering based on the user, rather than a blanket policy for all. I can do this to a certain degree by assigning static IP's to each device and using clientless authentication, but means each device has to be added manually, and until they are I have no visibility of who's device has connected.
My setup currently comprises of
- Sophos XG 17
- A wireless network using WPA2 Enterprise security - authenticating against a RADIUS windows server 2012 R2 (Hardware is TP-Link EAP110 - managed by Wireless Controller software EAP Controller running on it's own server)
- Wireless devices (e.g. Mobile Phones) can connect using their work AD credentials
- When I've installed the STAS onto the Domain Controller it doesn't pick up any active users as the RADIUS authentication event logs aren't against the right event ID (the STAS only appears to detect workstation login / logoff security events)
- When I try to forward accounting information from the RADIUS server to the Sophos XG firewall it gives me the option of loading into a SQL database (which it cannot find), or a log file which requires a folder path the Sophos XG does not have.
Any ideas?
Cheers
Matt
This thread was automatically locked due to age.