Garacesh Posted December 9, 2020 Posted December 9, 2020 We've recently had an XG box fitted and I can't say I've got many complaints. BUT! (because there's always a but ) I'm having some difficulty tagging WiFi traffic from non-domain devices to a user. All of our on-domain Windows devices authenticate over STAS, but that's obviously not an option for phones and iPads and the like. So, I connect an iPad to the WiFi, give it the Root CA certificate, and browse to a website. It works. Awesome! Except it doesn't know who I am, even though I put a username and password into the Authentication settings of the WiFi network (domain\user format, though I've also tried the user@domain format that Sophos displays). If I go to a site that's blocked, I get the correct block page, but it says my username is blank. Web filter logs confirm this, there's no username. So, it's clearly putting me on the Pupil filtering, since Default group is set as the kids in Configure / Authentication / Services I faffed about with settings for a bit, and got it to throw a credential prompt. I think this was after I turned AD SSO on for WiFi. On my iPad where I had credentials: awesome! It's now logging the user. On my Android phone where I had no credentials set, it asked for credentials. Yay! ... except, that's not quite right. Because if I delete the user credentials (or just make the username bogus) it still allows traffic. And it still tags traffic to that user. Even if I turn AD SSO off, it still tags traffic to that user. So it's obviously not looking at the credentials at all. It's just throwing that credential prompt once and then tagging everything to that user, which is probably functionally correct, it's not technically correct. MAC address binding is disabled for the user groups (and checking there's no MAC address list for my test users, there isn't), so it ain't that.. Bit stumped now
BKGarry Posted December 9, 2020 Posted December 9, 2020 Do you have RADIUS Accounting passing through from your Windows Network Policy Server to the SophosXG box? I am just going to check my settings and will screenshot them in a moment to you
BKGarry Posted December 9, 2020 Posted December 9, 2020 OK hopefully the screenshots make sense to you here: Windows NPS Server Sophos XG
Wave9_Lee Posted December 10, 2020 Posted December 10, 2020 Hi Garacesh, If you enable the Captive Portal on your unauthenticated (pupil) firewall rule, un-authenticated users (iPads, iPhones..) will be prompted to log in with valid credentials before they can access the Internet. Once they're authenticated, they'll then hit the same firewall rule as your Windows devices and the username will be logged. (Just to say that you will need the certificate pushed out if you have SSL inspection enabled...). Alternatively, there's the Sophos Network Agent which is a downloadable app, which does the same kind of thing. More details on that can be found here: https://apps.apple.com/us/app/sophos-network-agent/id1025058173
Garacesh Posted December 11, 2020 Author Posted December 11, 2020 If you enable the Captive Portal on your unauthenticated (pupil) firewall rule, un-authenticated users (iPads, iPhones..) will be prompted to log in with valid credentials before they can access the Internet. Aye, if I tell the unauthenticated rule to match users and use the captive portal it throws that login prompt to any and all web requests, but my suspicion is that doing it that way is likely to screw up apps on mobile devices (especially Apple kit) when it signs them out for inactivity etc. Although even with the SecurityAppliance_SSL_CA installed I still get a certificate error on the login page, NET::ERR_CERT_COMMON_NAME_INVALID*. I could just do it over HTTP but I don't really wanna do that on a page that's handling user credentials. Ideally, what I want is a passive solution, where you just slap the credentials into the proxy information and Sophos sees that and says "Yep, you're Joe Bloggs, go right ahead".. That way there's no faffing about for the end-user once it's set up. It looks like RADIUS might indeed be the way forward, something for me to do some digging on. For now I think I'm going to just have to leave them as they are - unauthenticated with pupil filtering, and a login button on the block page. I think it's reasonable middleground for now, until I've got the time to dig into it further. * which apparently actually means that the certificate isn't presenting a fully-qualified hostname, which looking at the certificate itself appears to be right.
Jamman960 Posted December 11, 2020 Posted December 11, 2020 We use radius with great success, I initially tried the app but it was very hit and miss. Our radius accounting is done via our wireless controller(ruckus) which points to the Sophos for accounting and NPS server for authentication, I imagine both ways are just as effective. James 1
Wave9_Lee Posted December 15, 2020 Posted December 15, 2020 Hi Garacesh, The Network Auth agent should be able to help with this scenario, as it would authenticate your users once the initial details are entered and that should be that. Otherwise for RADIUS, if you set up accounting on your wireless controller, then enter those details into the XG (IP of your WiFi controller /shared secret), and away you go. (note: Administration->Device Access: Radius SSO, should be enabled by default on the LAN zone, but you may want to check that also). Drop me a PM if you need more assistance, I can put you in touch with one of our engineers.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now