Jump to content

Recommended Posts

Posted

Hey all

 

Any suggestions on the best way to go with what mode to put the XG in, I want to go for the SSO I can see that there is a client that sits on the DC and sync up logins, I want it to be seem less for the user not having to login to the web browser and stuff.

 

Second question is

 

Has anyone setup there new xg while you still have UTM or other firewall in place. We have a limited time window that I will have to fit it so would like to setup and test it while still having my Sophos UTM in place

Posted

Wow, its almost like I've written this.

 

I've had my Sophos box in for about a week which is running alongside my SW box. Ours was setup with the client on the serer and it seems to work ok, not the slicking method but picks up the groups fine. (if you change the group you need to delete the record stored on the Sophos box)

 

Currently my SW is on 100.1 and my new Sophos is 100.252. Domain user have the IDEX client on and their proxy points to itself.

 

So my testing plan at present is to change the DHCP client to a static with a new default gateway of 100.252 on some of the machine and force a new proxy for some test users as No proxy.

 

We are a 3-18 school so I've got 4 test accounts but I've only tried the junior kids so far... and I've changed my admin account to use Sophos too.

 

My SW runs out on the 16th June so I am on a tight turnaround too, May Bank will be a rush.

 

I should be able to just change the Default gateway on my DHCP server to 252 and still use the SW proxy settings till I switch over..... or if I am 100% certain I might just change the IP of the Sophos box to 100.1 and decommission it.

 

I've still got my BYOD devices and Chromebooks to sort out.....and the unauthenticated clients.

 

PS. The logging on Sophos is superb!!!

Posted
Hey all

 

Any suggestions on the best way to go with what mode to put the XG in, I want to go for the SSO I can see that there is a client that sits on the DC and sync up logins, I want it to be seem less for the user not having to login to the web browser and stuff.

 

Second question is

 

Has anyone setup there new xg while you still have UTM or other firewall in place. We have a limited time window that I will have to fit it so would like to setup and test it while still having my Sophos UTM in place

 

I'm wanting to do the same thing, so we can smoothly migrate to XG. I asked a similar question on the Sophos Community some time ago - not sure if this is what you want to do also but my plan was a non-starter due to asynchronous routing issues:

 

https://community.sophos.com/products/xg-firewall/f/sophos-utm-to-xg-migration/110325/running-xg-alongside-utm

Posted
Subscribed - Watching with interest due to also taking this path in August. I would be interested to see how you sort your BYOD and Chromebooks out.
Posted
I'd be more inclined to re-address the XG to your current default gateway, there's going to less to worry about in getting round everything that might have a fixed IP address/gateway set. Just remember to update the XG IP address in the STAS client on your AD server(s).
Posted

I've changed our DHCP now to point to our new Sophos box. Issues initially as clients without the proxy or stuff like Outlook stopped working until I added them to the web filer properly. Skype wasn't working too so I am going through adding all the office365 exceptions again. (cant see a way to bulk add these annoyingly)

Today I swapped over the office staff to Sophos and removed the proxy. All seemed well, I am just getting some issues with clientless devices I missed off my list.. card machine, alarm system.

I should be okay to fully migrate at half term fully.

Its actually a really good system, much better than Smoothwall and super fast changing any settings. Only annoying thing is the box powers up the fans whenever you make any changes. Its not in the rack yet so I so I am hoping it wont be as intrusive when in there.

Reporting is a different level too, can't stress enough how brilliant it is in comparison.

  • Thanks 1
  • 2 weeks later...
Posted

what issues are you seeing, i will be installing my new xg in a couple of weeks.

 

i will probably need some support from sophos :0

Posted

Simple things are taking ages or I cant get to work.

 

Talking between a vlan and my internet logon page has taken ages to sort and the rule we got to work makes no logical sense.

I cant get the vlan to go to the user portal logon page, it works on the normal lan.

The Chromebook thing isn't working even though I followed the awful Sophos support page instructions.

The reports are quick but the safeguarding stuff isn't great unless you want 10 reports a day.

The box is stupidly noisy whenever you make a simple change.. I don't know what the life cycle of the fans are.

Some reason Outlook seems to crash out with no connection, if you browse the internet it comes back eventually.

 

Some of its down to me trying to rush it but I have 2 hours to get the the vlans working for our guest WIFI

 

Oh and I cant work out how Ruckus can talk to it.

Posted
That was the great think with Smoothwall & Ruckus with BYOD you could authenticate once using the Radius on Smoothwall. I was hoping the Sophos XG would work in the same sort of way but I hope we may be able the forward the radius requests from a Windows Radius server to the Sophos XG? I will find out during the summer holidays.
Posted
That was the great think with Smoothwall & Ruckus with BYOD you could authenticate once using the Radius on Smoothwall. I was hoping the Sophos XG would work in the same sort of way but I hope we may be able the forward the radius requests from a Windows Radius server to the Sophos XG? I will find out during the summer holidays.

 

I logged a case with Sophos asking about it, I did find someone on the Sophos community who said they had it working but they never replied. I've gone with the captive portal for now which is okay and you can HTML the logon page to make it pretty.... except for some reason its blocking the link to the MITM certificate so half the kids cant use the BYOD. As soon as they authenticate they can access the link so its being blocked somewhere.

 

There's been a lot of complaints of how unreliable the internet is at present and Outlook just dies sporadically... I was going to power up my Smoothwall box and stick that back on till the end of term as I know that works but after I turned it off it wont power back on... got 8 years out of it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...