Jump to content

Recommended Posts

Posted

Good Afternoon,

 

I'm having a bit of a nightmare and looking to speak with people who are running a Unifi Wireless system with Sophos XG for firewall and filtering.

 

If you could reach out to me that would be great, struggling for a couple of weeks now with this problem and have run out of ideas!

 

Cheers

Posted

One of my schools has unifi WiFi, and most of my schools have unifi switching, all behind a single XG pair of XGs.

 

What issue are you having?

Posted

So I was having issues with RADIUS SSO but after working late last night and making some changes it appears I have made good progress in resolving the issue. I'm wary of saying its fully resolved until we've had a few more days running without issue.

 

There was a recent firmware update on the Unifi network that I applied as part of the fix. We also had a strange issue with our Always on VPN which was not helping the issue so after sorting that it seems to have helped also.

Posted
There have been issues with Unifi and Radius, so I'd say the issue is probably nothing to do with the XG.

 

Yeah I agree. Looking at the network today it looks much better and everything seems to be doing what it should.

Posted
So I was having issues with RADIUS SSO but after working late last night and making some changes it appears I have made good progress in resolving the issue. I'm wary of saying its fully resolved until we've had a few more days running without issue.

 

There was a recent firmware update on the Unifi network that I applied as part of the fix. We also had a strange issue with our Always on VPN which was not helping the issue so after sorting that it seems to have helped also.

 

Can you expand on the issues you were facing?

Posted
Can you expand on the issues you were facing?

So our users would authenticate with the wireless and the NPS server forwards the accounting packets onto the XG for the web filter. We found as the users were roaming around site the XG would drop the user auth and users were getting a basic heavily restricted unauthenticated web filter.

Posted

I've had some roaming issues but I put it down to random mac setting on my phone, sometimes it just doesn't want to connect at all.

 

Had an issue in a corridor today where everything looked ok according to the controller when when I stood underneath it I couldn't connect. Had to power reboot the switch and the AP's and its fine now.

Posted
So our users would authenticate with the wireless and the NPS server forwards the accounting packets onto the XG for the web filter. We found as the users were roaming around site the XG would drop the user auth and users were getting a basic heavily restricted unauthenticated web filter.

 

When this happened, within the XG under Authentication >Users did the users appear in the ‘Open Group’ (assuming you left this as your default group) instead of their correctly ordered group as per Authentication >Groups ?

Posted
So I was having issues with RADIUS SSO but after working late last night and making some changes it appears I have made good progress in resolving the issue. I'm wary of saying its fully resolved until we've had a few more days running without issue.

 

There was a recent firmware update on the Unifi network that I applied as part of the fix. We also had a strange issue with our Always on VPN which was not helping the issue so after sorting that it seems to have helped also.

 

What version of unifi are you on now? We have issues too with SSO and our smoothwall which sound very similar to yours. Have been advised not to run firmware updates though.

Posted
When this happened, within the XG under Authentication >Users did the users appear in the ‘Open Group’ (assuming you left this as your default group) instead of their correctly ordered group as per Authentication >Groups ?

 

So under that I had users listed twice with the school.internal UPN and public.school.org UPN as well. The school UPN was associated with the correct filter group but the public was not.

Posted
What version of unifi are you on now? We have issues too with SSO and our smoothwall which sound very similar to yours. Have been advised not to run firmware updates though.

 

I have upgraded to 4.3.28.11361 on the APs and Cloud Key is on 6.0.45-14358-1.

  • 5 months later...
Posted

Hi there

 

I also use both Unifi wireless system and have just configured Always On VPN and have what sounds like the same issue with the XG dropping user authentication and have been troubleshooting this for weeks. Any pointers in terms of a resolution would be much appreciated as I am really baffled by this.

 

Many Thanks

 

Adam Clarke

Posted
Hi there

 

I also use both Unifi wireless system and have just configured Always On VPN and have what sounds like the same issue with the XG dropping user authentication and have been troubleshooting this for weeks. Any pointers in terms of a resolution would be much appreciated as I am really baffled by this.

 

Many Thanks

 

Adam Clarke

 

My resolution seemed to be just updating the Unifi firmware (I have not updated since either though). Interesting that you have just configured AOVPN. I also have that configured and one thing I noticed around the same time as this was that my clients were still connecting to the AOVPN even whilst in school. Digging into that I noticed I had an internal DNS record for it so removing that stopped the VPN from connecting internally and combined that with the Unifi upgrade it could well have contributed to the solution.

Posted

Hi there

 

Thanks for the quick reply, my Unifi Console is fully up to date. I have tested a laptop for my own piece of mind and the VPN is not connecting internally so it does not look like the issue but I will still look into this just in case of a random issue. Where in DNS did you find the record you removed as I am not sure where I would find it if it does exist?

 

Thanks again

 

Adam

Posted
So we have 2 lookup zones, internal domain name and public domain name. In the public domain name zone there was an A record pointing to the server for the public DNS name of our VPN server. It was all setup before I started working here. Once I removed that it automatically stopped laptops here connecting to VPN when in school. Which I suppose could have been an issue as the Sophos XG reads the AD logs it could see different logins or from a different UPN.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...