This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AD-SSO domain join not working

Hi guys,

I tried to connect my Sophos UTM 9 with our DC, so that I can use SSO with standard proxy feature.

Sadly Sophos tells me all the time, that domain join not working. Thats why I searched the discussions and the Knowledgebase and find some tips but nothing worked for me.

Quite odd is that the sophos utm shows up in computers section of dc, but the sso feature is still not working.


I checked system times of both systems (using the same ntp server), time zones, hostname is FQDN, utm is registered in dns and the dns forwarder is set up like described in DNS Best Practice (https://www.sophos.com/de-de/support/knowledgebase/120283.aspx)

We´re using 6 DCs in our domain. Main dc is using W2K12 but there is also a DC using W2K8R2. I saw the Workaround (https://www.sophos.com/de-de/support/knowledgebase/121344.aspx) but its not so easy to reboot he system.


My Questions:

  • Why does the SSO / domain join is not working, although the utm shows up in DC computers?
  • Which dc is used by utm for joining the domain?
  • If the problem is caused by W2k12 and SMB, is there any chance to use the W2K8R2 Server instead (this server is set up under dns request router s in utm)?
  • Any other ideas that I might missed?

Thanks for your support.



This thread was automatically locked due to age.
Parents
  • Hi, Sebastian, and welcome to the UTM Community!

    That DNS Best Practice article was lifted from a post I maintain over a year ago, so I don't know if the person that's taking care of the KB article has integrated the changes made to my post - DNS Best Practice.  You might want to compare your current setup to that.

    If you've also followed #1 in Rulz, then I don't think you have a problem you can solve in WebAdmin although changing the AD Server configured on the 'Server' tab to the W2K8 server and changing your Request Route to the same might work.

    Cheers - Bob

Reply
  • Hi, Sebastian, and welcome to the UTM Community!

    That DNS Best Practice article was lifted from a post I maintain over a year ago, so I don't know if the person that's taking care of the KB article has integrated the changes made to my post - DNS Best Practice.  You might want to compare your current setup to that.

    If you've also followed #1 in Rulz, then I don't think you have a problem you can solve in WebAdmin although changing the AD Server configured on the 'Server' tab to the W2K8 server and changing your Request Route to the same might work.

    Cheers - Bob

Children
No Data