Jump to content

Recommended Posts

Posted
Have a bit of a random issue with STAS in that random users get kicked off the internet and have to sign in via the captive protal to gain access. All users are in the same authentication group and all computers have the same settings. However the majority work fine but random ones get kicked off, anyone come across this?
Posted
Have a bit of a random issue with STAS in that random users get kicked off the internet and have to sign in via the captive protal to gain access. All users are in the same authentication group and all computers have the same settings. However the majority work fine but random ones get kicked off, anyone come across this?

Is STAS set to poll using WMI? Check STAS->STA Collector | Workstation Polling Method.

If it is, check that WMI communication is allowed to your clients: STAS->Advanced->WMI Verification (and enter your client IP address that's having difficulty staying authenticated). If that's got issues, ensure that WMI is being allowed to your clients:

 

https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/125318/sophos-firewall-best-practice-for-stas#mcetoc_1esth6tqs1m

  • 1 month later...
Posted

I have a similar problem also. For the majority it works fine, but in a class of say 34 computers, I always end up with 4/5 which have to manually input their username / password into the captive portal. WMI is set as the polling method & WMI verification works fine on the machines in question.

 

I'm going to setup STAS again from scratch following the guidance from Sophos

Posted
We have turned off the WMI polling on the XG box and that appears to have stopped the issue as it is set to check back veery ten minutes and if there is a delay the user is logged out. All is working as it should at the moment.
Posted
We have turned off the WMI polling on the XG box and that appears to have stopped the issue as it is set to check back veery ten minutes and if there is a delay the user is logged out. All is working as it should at the moment.

 

How did you do this? I'm running out of ideas now! Still having intermittent issues with random PC's not automatically signing in with SSO.

Posted
We got our internet provider to turn it off as they control this area of the XG. There are two authentication methods that are running on the box, one was WMI and if the XG dddin't get a timely repsonse every ten minutes the user was logged out, the other was data and the user had to use 10mb per hour. We had WMI turned off and the data limit dropped to 500k.
  • Thanks 1
Posted

More headaches with STAS :( I've ended up disabling it temporarily & blanket applying filtering rules to all devices, STAS is being way too inconsistent & is causing problems.

 

This started when I migrated STAS to a new DC (Windows Server 2022) - Sophos have stated that they have not tested STAS on Server 2022 yet, potentially why issues have arisen now? I've set it up the exact same way it was on the previous DC (Server 2012). Going to open a support ticket with Sophos to see if they can help at all..

Posted
More headaches with STAS :( I've ended up disabling it temporarily & blanket applying filtering rules to all devices, STAS is being way too inconsistent & is causing problems.

 

This started when I migrated STAS to a new DC (Windows Server 2022) - Sophos have stated that they have not tested STAS on Server 2022 yet, potentially why issues have arisen now? I've set it up the exact same way it was on the previous DC (Server 2012). Going to open a support ticket with Sophos to see if they can help at all..

 

Do you use Sophos Endpoint (or whatever it’s called now) we use this with synchronised security and the authentication has worked flawlessly

Posted
Do you use Sophos Endpoint (or whatever it’s called now) we use this with synchronised security and the authentication has worked flawlessly

 

We do have Sophos Endpoint AV, how do you go about setting this as the primary auth method?

Posted (edited)

I had quite a few problems with STAS when i first moved to Sophos, spent a while troubleshooting and i've now got it working perfectly. I'm still not happy with the permissions it requires but i think i've limited it about as much as i can really. I really didn't like Sophos documentation or lack of advice when it came to setting up STAS when it came to what access it needed, so i've worked on that a bit.

 

I've got STAS installed on my DCs for the agent and then I've made a dedicated VM for the collector.

 

Configuration in the firewall (172.18.66.8 is the collector server):

Screenshot 2023-10-19 091533.png

DCs have a service account of svc_sophosfirewall which has no special permissions for reading AD.

 

In the collector and agent on the General tab, make sure NetBIOS name is in full caps.

 

Collector configuration:

Screenshot 2023-10-19 091804.png

 

Agent configuration on my DC's:

Listed each subnet/vlan clients login to individually rather than one large range, found this more reliable.

Screenshot 2023-10-19 091959.png

 

Key part though, I've made a service account for the agent and a service account for the collector. The collector I've made a service account called svc_sophoscollector and needs to be able to read information from clients, so it needs permissions relevant to that level of capability...I've begrudgingly put that in a security group which is added to clients with local admin rights. The agent i've currently got set as a domain admin, but it's only used on the DC. Further added the sophoscollector account to deny local login among a few other bits.

 

There's a bit more on service accounts here: https://community.sophos.com/sophos-xg-firewall/f/discussions/117357/lua-for-stas-service-account I've not tried going down the link at the bottom to start sorting out permissions in a more specific way for WMI access (On the to-do list, but it's been there a while) by default Sophos documentation seems to have people installing the STAS service with domain admin, then that domain admin is reading from the DC security log and remote clients, but i didn't like that.

 

I've not had any issues with STAS in the past 6+ months of doing this.

 

EDIT:

So in terms of accounts

svc_sophosfirewall - Generic account on firewall

svc_sophosagent - STAS Agent on DCs which is a member of domain admins

svc_sophoscollector - STAS collector service account on the collector VM, no special permissions assigned, but local admin given to domain clients for WMI access - This can potentially be replaced by specifying WMI specific permissions.

 

EDIT2:

Obviously make sure you've enabled all the right Audit logging events in group policy for your DCs too, for the Agent to read from.

Edited by mrbios
  • Thanks 2
Posted

It's working!!

 

I believe I overlooked something, or misunderstood the login exclusions section. In the login IP exclusions, I added all of our server IP addresses, followed by the subnet. So 10.25.160.5/20 for example. This was either blocking the domain controllers from reporting the logins, or just excluding the entire subnet? who knows. I'm just glad its working again now!

 

Screenshot 2023-10-19 112004.png

  • 3 weeks later...
Posted
I had quite a few problems with STAS when i first moved to Sophos, spent a while troubleshooting and i've now got it working perfectly. I'm still not happy with the permissions it requires but i think i've limited it about as much as i can really. I really didn't like Sophos documentation or lack of advice when it came to setting up STAS when it came to what access it needed, so i've worked on that a bit.

 

I've got STAS installed on my DCs for the agent and then I've made a dedicated VM for the collector.

 

Configuration in the firewall (172.18.66.8 is the collector server):

[ATTACH=CONFIG]70120[/ATTACH]

DCs have a service account of svc_sophosfirewall which has no special permissions for reading AD.

 

In the collector and agent on the General tab, make sure NetBIOS name is in full caps.

 

Collector configuration:

[ATTACH=CONFIG]70118[/ATTACH]

 

Agent configuration on my DC's:

Listed each subnet/vlan clients login to individually rather than one large range, found this more reliable.

[ATTACH=CONFIG]70119[/ATTACH]

 

Key part though, I've made a service account for the agent and a service account for the collector. The collector I've made a service account called svc_sophoscollector and needs to be able to read information from clients, so it needs permissions relevant to that level of capability...I've begrudgingly put that in a security group which is added to clients in the "Remote Management Users" group. The agent i've currently got set as a domain admin, but it's only used on the DC. Further added the sophoscollector account to deny local login among a few other bits.

 

There's a bit more on service accounts here: https://community.sophos.com/sophos-xg-firewall/f/discussions/117357/lua-for-stas-service-account I've not tried going down the link at the bottom to start sorting out permissions in a more specific way for WMI access (On the to-do list, but it's been there a while) by default Sophos documentation seems to have people installing the STAS service with domain admin, then that domain admin is reading from the DC security log and remote clients, but i didn't like that.

 

I've not had any issues with STAS in the past 6+ months of doing this.

 

EDIT:

So in terms of accounts

svc_sophosfirewall - Generic account on firewall

svc_sophosagent - STAS Agent on DCs which is a member of domain admins

svc_stascollector - STAS collector service account on the collector VM, no special permissions assigned. Add to the "Remote Mananagement Users" group of all local machines in order to allow WMI access.

 

EDIT2:

Obviously make sure you've enabled all the right Audit logging events in group policy for your DCs too, for the Agent to read from.

 

Just updated this. None of this seems to be documented by Sophos in a "best practice" way of setting up STAS. The Sophos guide has to granting far too many permissions to the service accounts involved, or just doesn't give any description of what permissions are needed..... Changed the stascollector account to remove from local admins, it only needs to be in "remote management users" in order to read WMI. I think this is the minimal permissions possible for everything to work correctly.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...