lmrogers Posted April 6, 2021 Posted April 6, 2021 Morning All, Been spending the weekend setting up my new Sophos XG firewall. So far absolutely loving it. Do have a quick question though, I've setup RADIUS SSO for our wireless networks including BYOD and got the Windows NPS Server forwarding the accounting through to the XG. With our BYOD network though I keep running into the issue of the Sophos CA cert not being installed and blocking internet access. How have others gone about getting around this issue or distributing the cert? Cheers
altecsole Posted April 6, 2021 Posted April 6, 2021 We distribute the certificate using Group Policy. For BYOD devices, we've put the certificate on the school website, with instructions on how to install it. We do allow limited access to some sites without SSL inspection, including our website, so users can connect to WiFi and still get to the certificate.
BKGarry Posted April 6, 2021 Posted April 6, 2021 I have a seperate VLAN for BYOD with the SSL Inspection disabled, so it doesn't ask for the sophos cert, it does still give the warning about the windows cert at the initial connection
lmrogers Posted April 6, 2021 Author Posted April 6, 2021 I have a seperate VLAN for BYOD with the SSL Inspection disabled, so it doesn't ask for the sophos cert, it does still give the warning about the windows cert at the initial connection Are their any issues with the filtering with SSL Inspection disabled? Do they still receive the Sophos blocked page?
BKGarry Posted April 6, 2021 Posted April 6, 2021 If it is a non SSL site they do get the block page, if it is an SSL site they get a site cannot be reached page in their browser.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now