Simcfc73 Posted May 29, 2019 Posted May 29, 2019 Hi, Next snag. Has anyone got Chromebooks and the XG playing nicely. What's it supposed to do? I've followed the Sophos article and setup the cert and the firewall but its not playing... is it supposed to be SSO where you logon to the Chromebook and it automatically logs into Sophos or is it a dual prompt? Following the tutorial it doesn't even get to the prompt unless I open the FW up more.
Simcfc73 Posted July 17, 2019 Author Posted July 17, 2019 *bump* I was going to redo another thread but thought I would bump this. According to these articles its soooooooo easy to setup but its hitting the first firewall rule and not getting ot the logon page.. I've added the store and the API setting to the rule but the Chromebook just loops trying to connect all the time. https://www.sophos.com/en-us/support/products/xg-firewall/how-to-library.aspx#Authentication https://community.sophos.com/kb/en-us/133044
TechBeard Posted September 25, 2020 Posted September 25, 2020 Hi, How did you get on with this in the end? We found that the guide was incorrect and the Sophos professional services team had to make up some other rules. They said they would feed this back to the product manual team. We have found the Sophos Chromebook authentication pretty dreadful compared to things like Smoothwall and Linewize etc. Lots of dropping out etc.
Wave9_Lee Posted September 25, 2020 Posted September 25, 2020 This should be pretty straightforward, and we've done it many times, no issues.
Simcfc73 Posted September 25, 2020 Author Posted September 25, 2020 Ours doesn't work, we use Azure as a auth provider for Google so it can't talk to it.
TechBeard Posted September 28, 2020 Posted September 28, 2020 I would agree, it should be - but unfortunately most of the support agents I've talked to at Sophos don't know what a Chromebook is which makes the whole process quite difficult. "Can we RDP to it" - no its a Chromebook, it cannot be RDPed to "can we please browse to the C Drive to check the WMI logs" - no, its a chromebook, they dont support WMI "can we please check its logon event in AD logs" - no its a chromebook, it authenticates with Google, not AD
Jaan Posted September 28, 2020 Posted September 28, 2020 We have the chromebooks connect to a specific SSID which has a student policy on it. This works fine but doesn't give user level reporting.
TechBeard Posted September 28, 2020 Posted September 28, 2020 We do have a separate SSID for Chromebooks but authenticating using the Sophos Chromebook app. We could not risk not having user level reporting. We have so many safeguarding investigations it just would not be a feasible workaround
Primus Posted September 28, 2020 Posted September 28, 2020 We have the chromebooks connect to a specific SSID which has a student policy on it. This works fine but doesn't give user level reporting. Well it's not fine is it as if you can't report on which site was accessed by which student your filtering and monitoring is only filtering - you're meant to monitor too.
Jaan Posted September 29, 2020 Posted September 29, 2020 Well it's not fine is it as if you can't report on which site was accessed by which student your filtering and monitoring is only filtering - you're meant to monitor too. Depends if you're running impero or Sophos Chromebook app not......
Primus Posted September 29, 2020 Posted September 29, 2020 Depends if you're running impero or Sophos Chromebook app not...... Your original post said you didn't have user level reporting....
Jaan Posted September 29, 2020 Posted September 29, 2020 No, I didn't say we don't have student leveling filtering. I implied that the method I posted doesn't offer it. The OP was referencing on connecting Chromebooks to a Sophos XG (i'm assuming hey have Sophos APs). The method we use to connect to Sophos XG doesn't offer user level reporting without a 3rd party option or if you have subscribed to the Sophos Mobile module.
Primus Posted September 29, 2020 Posted September 29, 2020 No, I didn't say we don't have student leveling filtering. I implied that the method I posted doesn't offer it. The OP was referencing on connecting Chromebooks to a Sophos XG (i'm assuming hey have Sophos APs). The method we use to connect to Sophos XG doesn't offer user level reporting without a 3rd party option or if you have subscribed to the Sophos Mobile module. That isn't what you said though: "This works fine but doesn't give user level reporting." If you're recommending doing that but then getting your user level reporting from somewhere else you need to be explicit otherwise someone following your suggestion is liable to cause themselves issues.
Jaan Posted September 29, 2020 Posted September 29, 2020 That isn't what you said though: "This works fine but doesn't give user level reporting." If you're recommending doing that but then getting your user level reporting from somewhere else you need to be explicit otherwise someone following your suggestion is liable to cause themselves issues. Maybe we're looking at this differently, If i offer a suggestion and also make you aware that it doesn't offer user level filtering what's the issue? i don't know if the OP has access to Sophos Mobile or Impero. So i'm making them aware that my method DOESN'T offer user level report. anyway..... to clarify. The method i posed above Doesn't offer any user level filtering. It only allows a chromebook to be connected to a specific SSID with a web filtering policy applied to it. You'll have to use Sophos Mobile or a third part method to ensure user level reporting is functional.
Primus Posted September 29, 2020 Posted September 29, 2020 (edited) Maybe we're looking at this differently, If i offer a suggestion and also make you aware that it doesn't offer user level filtering what's the issue? i don't know if the OP has access to Sophos Mobile or Impero. So i'm making them aware that my method DOESN'T offer user level report. anyway..... to clarify. The method i posed above Doesn't offer any user level filtering. It only allows a chromebook to be connected to a specific SSID with a web filtering policy applied to it. You'll have to use Sophos Mobile or a third part method to ensure user level reporting is functional. My issue is that not having user level filtering is a big problem - if you'd said it doesn't have user level and you will need to add this with another product it would have been clearer. Not everyone is always aware of all the requirements with regards to filtering and monitoring so a colleague may think that filtering without user level filtering or reporting was ok as a result of your post - it came across to me like that - that you ony filter Chromebooks like that. I just wouldn't want someone to rely on advice on here that wasn't fully clear. Edited September 29, 2020 by Primus
paulkerton Posted September 29, 2020 Posted September 29, 2020 And this is why people should seriously consider moving to cloud based filtering solutions like Securly or Lightspeed Relay, especially for devices like Chromebooks and especially if they go off-site.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now