This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM 9.409-09 Webfilter SSO trusted Domains (Domain B not working)

Hello,

 

i have installed a new HA System.

Configured DNS Forwarder to my 2 AD-Server in Domain A

Added Request Routing for both Domains to the AD-Server from Domain A

The 2 AD-Server in Domain A have a two way trusted relationship with the AD-Server from Domain B, this is working without any Problems in the Windows world!

The UTM is joined to Domain A.

In Domain A i have 3 "Global Security Groups" for different webfilters.

In this groups have Members from Domain A and Domain B.

Proxy mode is standard.

 

When i start my browser with an user from Domain A, everything is working with the correct filter, in the log i see the username, group and the domain (Domain A).

When i start my browser with an user from Domain B, it is not working and i get the defaukt fallback policy. In the log i see the correct username an domain (Domain B), but the group field is empty.

And here i think is the problem, without a group the webfilter policy cant apply the correct filter and go to the fallback policy.

 

Maybe anyone has the solution for me?



This thread was automatically locked due to age.
  • Hi, Dominic, and welcome to the UTM Community!

    If you change DNS & DHCP to DNS best practice, does your issue persist?

    Bear in mind that SSO Authentication and Backend Group membership do not use the same tools in the UTM.  If the users in Domain B are not members of the Security Group in Domain A, the situation you described could occur.  Consider Configuring HTTP/S proxy access with AD SSO.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA