Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Security bug? SSL VPN UTM 9.100-12 multiple Active Directories

Hello

When im configuring two active directories with the new ssl vpn profile based system, it isnt possible to dedicate one of this profiles/users/groups onto one of this active directories. 

In my scenario this is a huge security bug:

When my "active directory 1" have the same username in there then my "active directory 2", it is possible to connect with the "active directory 2" username and the password from the user on "active directory 2" (other password then the same username on "active directory 1") to the active directory 1 users ssl vpn and because of that to the wrong customer network (active directory profile 1 customer network). Its random, sometimes my user from "active directory 2" is connected to the "active directory 2" network, sometimes to the "active directory 1" network...

Knows anyone something about this situation/problem?

thank you for help!
kind regards


This thread was automatically locked due to age.
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?