Uber22 Posted May 10, 2019 Posted May 10, 2019 Hey all Any suggestions on the best way to go with what mode to put the XG in, I want to go for the SSO I can see that there is a client that sits on the DC and sync up logins, I want it to be seem less for the user not having to login to the web browser and stuff. Second question is Has anyone setup there new xg while you still have UTM or other firewall in place. We have a limited time window that I will have to fit it so would like to setup and test it while still having my Sophos UTM in place
Simcfc73 Posted May 14, 2019 Posted May 14, 2019 Wow, its almost like I've written this. I've had my Sophos box in for about a week which is running alongside my SW box. Ours was setup with the client on the serer and it seems to work ok, not the slicking method but picks up the groups fine. (if you change the group you need to delete the record stored on the Sophos box) Currently my SW is on 100.1 and my new Sophos is 100.252. Domain user have the IDEX client on and their proxy points to itself. So my testing plan at present is to change the DHCP client to a static with a new default gateway of 100.252 on some of the machine and force a new proxy for some test users as No proxy. We are a 3-18 school so I've got 4 test accounts but I've only tried the junior kids so far... and I've changed my admin account to use Sophos too. My SW runs out on the 16th June so I am on a tight turnaround too, May Bank will be a rush. I should be able to just change the Default gateway on my DHCP server to 252 and still use the SW proxy settings till I switch over..... or if I am 100% certain I might just change the IP of the Sophos box to 100.1 and decommission it. I've still got my BYOD devices and Chromebooks to sort out.....and the unauthenticated clients. PS. The logging on Sophos is superb!!!
colly72 Posted May 15, 2019 Posted May 15, 2019 Hey all Any suggestions on the best way to go with what mode to put the XG in, I want to go for the SSO I can see that there is a client that sits on the DC and sync up logins, I want it to be seem less for the user not having to login to the web browser and stuff. Second question is Has anyone setup there new xg while you still have UTM or other firewall in place. We have a limited time window that I will have to fit it so would like to setup and test it while still having my Sophos UTM in place I'm wanting to do the same thing, so we can smoothly migrate to XG. I asked a similar question on the Sophos Community some time ago - not sure if this is what you want to do also but my plan was a non-starter due to asynchronous routing issues: https://community.sophos.com/products/xg-firewall/f/sophos-utm-to-xg-migration/110325/running-xg-alongside-utm
AliG Posted May 15, 2019 Posted May 15, 2019 Subscribed - Watching with interest due to also taking this path in August. I would be interested to see how you sort your BYOD and Chromebooks out.
Wave9_Tim Posted May 16, 2019 Posted May 16, 2019 I'd be more inclined to re-address the XG to your current default gateway, there's going to less to worry about in getting round everything that might have a fixed IP address/gateway set. Just remember to update the XG IP address in the STAS client on your AD server(s).
Simcfc73 Posted May 17, 2019 Posted May 17, 2019 I've changed our DHCP now to point to our new Sophos box. Issues initially as clients without the proxy or stuff like Outlook stopped working until I added them to the web filer properly. Skype wasn't working too so I am going through adding all the office365 exceptions again. (cant see a way to bulk add these annoyingly) Today I swapped over the office staff to Sophos and removed the proxy. All seemed well, I am just getting some issues with clientless devices I missed off my list.. card machine, alarm system. I should be okay to fully migrate at half term fully. Its actually a really good system, much better than Smoothwall and super fast changing any settings. Only annoying thing is the box powers up the fans whenever you make any changes. Its not in the rack yet so I so I am hoping it wont be as intrusive when in there. Reporting is a different level too, can't stress enough how brilliant it is in comparison. 1
Simcfc73 Posted May 30, 2019 Posted May 30, 2019 After 2 weeks I rescind my praise. I miss my Smootwall box.
TechMonkey Posted May 30, 2019 Posted May 30, 2019 After 2 weeks I rescind my praise. I miss my Smootwall box. That sounds disappointing. Could you expand?
Uber22 Posted May 30, 2019 Author Posted May 30, 2019 what issues are you seeing, i will be installing my new xg in a couple of weeks. i will probably need some support from sophos :0
Arthur Posted May 30, 2019 Posted May 30, 2019 After 2 weeks I rescind my praise. I miss my Smoothwall box. One of the features I miss from our Smoothwall proxy is the ability to use regular expressions. On the XG the only place you can use them is in Web > Exceptions and that's it! https://community.sophos.com/kb/en-us/117316
Simcfc73 Posted May 30, 2019 Posted May 30, 2019 Simple things are taking ages or I cant get to work. Talking between a vlan and my internet logon page has taken ages to sort and the rule we got to work makes no logical sense. I cant get the vlan to go to the user portal logon page, it works on the normal lan. The Chromebook thing isn't working even though I followed the awful Sophos support page instructions. The reports are quick but the safeguarding stuff isn't great unless you want 10 reports a day. The box is stupidly noisy whenever you make a simple change.. I don't know what the life cycle of the fans are. Some reason Outlook seems to crash out with no connection, if you browse the internet it comes back eventually. Some of its down to me trying to rush it but I have 2 hours to get the the vlans working for our guest WIFI Oh and I cant work out how Ruckus can talk to it.
AliG Posted June 4, 2019 Posted June 4, 2019 That was the great think with Smoothwall & Ruckus with BYOD you could authenticate once using the Radius on Smoothwall. I was hoping the Sophos XG would work in the same sort of way but I hope we may be able the forward the radius requests from a Windows Radius server to the Sophos XG? I will find out during the summer holidays.
Simcfc73 Posted June 4, 2019 Posted June 4, 2019 That was the great think with Smoothwall & Ruckus with BYOD you could authenticate once using the Radius on Smoothwall. I was hoping the Sophos XG would work in the same sort of way but I hope we may be able the forward the radius requests from a Windows Radius server to the Sophos XG? I will find out during the summer holidays. I logged a case with Sophos asking about it, I did find someone on the Sophos community who said they had it working but they never replied. I've gone with the captive portal for now which is okay and you can HTML the logon page to make it pretty.... except for some reason its blocking the link to the MITM certificate so half the kids cant use the BYOD. As soon as they authenticate they can access the link so its being blocked somewhere. There's been a lot of complaints of how unreliable the internet is at present and Outlook just dies sporadically... I was going to power up my Smoothwall box and stick that back on till the end of term as I know that works but after I turned it off it wont power back on... got 8 years out of it.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now