Jump to content

lmrogers

Members
  • Posts

    521
  • Joined

  • Last visited

Everything posted by lmrogers

  1. Update: Issue resolved, was a combination of firmware upgrades and some slight network config changes. Huge thanks to the guys at Wave9 for assisting!
  2. I have upgraded to 4.3.28.11361 on the APs and Cloud Key is on 6.0.45-14358-1.
  3. So under that I had users listed twice with the school.internal UPN and public.school.org UPN as well. The school UPN was associated with the correct filter group but the public was not.
  4. So our users would authenticate with the wireless and the NPS server forwards the accounting packets onto the XG for the web filter. We found as the users were roaming around site the XG would drop the user auth and users were getting a basic heavily restricted unauthenticated web filter.
  5. Yeah I agree. Looking at the network today it looks much better and everything seems to be doing what it should.
  6. So I was having issues with RADIUS SSO but after working late last night and making some changes it appears I have made good progress in resolving the issue. I'm wary of saying its fully resolved until we've had a few more days running without issue. There was a recent firmware update on the Unifi network that I applied as part of the fix. We also had a strange issue with our Always on VPN which was not helping the issue so after sorting that it seems to have helped also.
  7. Good Afternoon, I'm having a bit of a nightmare and looking to speak with people who are running a Unifi Wireless system with Sophos XG for firewall and filtering. If you could reach out to me that would be great, struggling for a couple of weeks now with this problem and have run out of ideas! Cheers
  8. Quick update on this and looking for some more ideas if possible. Setup is a 32 Access Point Unifi wireless system, Sophos XG Filter, Windows Server NPS. Accounting is forwarded from the NPS Server to the Sophos XG Filter. I can see the start and stop messages being sent through a packet capture. Authentication continues to work fine but accounting appears to drop as the web filter from the Sophos XG appears to lose authentication. There is no interim account on the Unifi. I have managed to recreate the problem: laptop loses XG authentication and get blocked page in Location A, move to location B and XG reauthenticates, can access the appropriate sites for users web filter. Move back to Location A, works fine momentarily before then losing XG authentication again. I can also disconnect and reconnect the wireless in Location A to reauthenticate with the XG, this solves the problem for an undefined period of time. I'm running out of ideas what to try, if anyone has any help that would be great. Thanks!!
  9. Just running Wireshark capture on the NPS server I can see that in the Accounting-Request packets it is receiving a Framed-IP-Address.
  10. So that's how I have got it set and in the connection request policies, I have a wireless connections policy which forwards the accounting to the Sophos XG (Remote RADIUS Server Group). It's just a bit strange how it will randomly drop auth on the Sophos and pick it back up again.
  11. MESSAGE Apr 22 10:31:29.916557 [access_server]: handle_radius_account_req: request received from radius client NPSSERVERIPERROR Apr 22 10:31:29.916600 [access_server]: handle_radius_account_req: received radius accounting with status 2ERROR Apr 22 10:31:29.916624 [access_server]: (_sqlite_db_handle_get_liveuserinfo): GET_LIVEUSER_INFO_TO_LOGOUT found no entries for IP BYODIPADDRESS (sqrs 101)ERROR Apr 22 10:31:29.916635 [access_server]: (handle_external_logout_req_finish_free): SQLITE_REQ_GETLIVEUSERINFO query failedMESSAGE Apr 22 10:31:36.750328 [access_server]: handle_radius_account_req: request received from radius client NPSSERVERIPERROR Apr 22 10:31:36.750351 [access_server]: handle_radius_account_req: received radius accounting with status 2MESSAGE Apr 22 10:31:38.276044 [access_server]: handle_radius_account_req: request received from radius client NPSSERVERIPERROR Apr 22 10:31:38.276087 [access_server]: handle_radius_account_req: received radius accounting with status 1MESSAGE Apr 22 10:31:39.027107 [access_server]: handle_radius_account_req: request received from radius client NPSSERVERIPERROR Apr 22 10:31:39.027126 [access_server]: handle_radius_account_req: received radius accounting with status 1MESSAGE Apr 22 10:31:39.027169 [access_server]: (handle_req_no_password): User 18oelks with clienttype 23 already live, ignoring the requestMESSAGE Apr 22 10:31:40.377564 [access_server]: handle_radius_account_req: request received from radius client NPSSERVERIPERROR Apr 22 10:31:40.377606 [access_server]: handle_radius_account_req: received radius accounting with status 2MESSAGE Apr 22 10:31:43.796939 [access_server]: handle_radius_account_req: request received from radius client NPSSERVERIPERROR Apr 22 10:31:43.796962 [access_server]: handle_radius_account_req: received radius accounting with status 2MESSAGE Apr 22 10:31:46.146647 [access_server]: handle_radius_account_req: request received from radius client NPSSERVERIPERROR Apr 22 10:31:46.146669 [access_server]: handle_radius_account_req: received radius accounting with status 1MESSAGE Apr 22 10:31:46.373840 [access_server]: handle_radius_account_req: request received from radius client NPSSERVERIPERROR Apr 22 10:31:46.373863 [access_server]: handle_radius_account_req: received radius accounting with status 2MESSAGE Apr 22 10:31:46.558429 [access_server]: handle_radius_account_req: request received from radius client NPSSERVERIPERROR Apr 22 10:31:46.558464 [access_server]: handle_radius_account_req: received radius accounting with status 2 This is a snippet of the access_server.log. Getting loads of these errors for some reason. But I am also seeing times where it can find the user as active so does not process the packet. Is anyone else having these issue with a Unifi wireless solution?
  12. Morning All, Has anyone managed to get any decent reports/alerts from a Sophos XG for safeguarding? I am just waiting on a price from Fastvue to see if that will be a viable option but be good to see if I can get some useful reports direct from the XG. Cheers
  13. Nope, not able to add a range. The Sophos documentation seems to point to having the NPS server forward the accounting from NPS which works just sporadically.
  14. Yeah its a bit of a shame, will work something out though. Cheers for the pointers.
  15. I've tried to do the same but can only seem to add 16 of my 32 APs as it then says it cannot add any more RADIUS clients than that.
  16. I'll give that a go. I do suspect that the issue is because of roaming around the different APs so that should sort that out.
  17. Sorry to resurrect an old thread but wondering if you can share the reports you generated for the safeguarding. Cheers
  18. No, I just have the NPS server listed there as that is where the accounting is being forwarded from. Should I put the APs in there and have accounting sent straight from the APs to the XG like that?
  19. Morning, Just wondering if someone can point me in the right direction. Over Easter, I setup a Sophos XG firewall and filter. Configured RADIUS SSO for our Unifi wireless system and confirmed that it is working. The RADIUS account is sent to the NPS server which then forwards the accounting onto the XG. However, the XG seems to be randomly dropping the user authentication and giving the users an unauthenticated web filter policy that I setup. It will eventually reauthenticate them on its own or by disconnecting and reconnecting the wireless triggers the XG to reauthenticate them. Thanks
  20. Cheers for the help guys. Found the problem, I was being stupid. Should just stop working late at night.
  21. Thanks, I corrected that and still have the same issue of not being able to access it. I can see in the log viewer that the firewall is allowing the traffic through to the public IP. Feel like I'm missing something really obvious.
  22. I have just setup a DNAT rule on an XG running SFOS 18.0.4 MR-4. I created the rule using the Server Access Assistant. I can see traffic being allowed through on the firewall rule that was created but am unable to see the webserver that I have created the NAT for. Not sure if there is something I'm missing. NAT Rule: Original Source: Any SNAT: Original Original Destination: Public IP (Added as an alias on the WAN interface) DNAT Webserver internal address Original Services: HTTPS PAT: Original Firewall Rule: Source Zone: Any Source Network: Any Destination Zone: LAN Destination Network: Webserver internal IP Services HTTPS Is there anything in this that is wrong?
  23. Are their any issues with the filtering with SSL Inspection disabled? Do they still receive the Sophos blocked page?
  24. Morning All, Been spending the weekend setting up my new Sophos XG firewall. So far absolutely loving it. Do have a quick question though, I've setup RADIUS SSO for our wireless networks including BYOD and got the Windows NPS Server forwarding the accounting through to the XG. With our BYOD network though I keep running into the issue of the Sophos CA cert not being installed and blocking internet access. How have others gone about getting around this issue or distributing the cert? Cheers
  25. Morning I've had Intune deploying certs for always on vpn authentication working well but today I've got a couple of computers that now will no long pickup the certificate. I followed this guide to setup the NDES and SCEP deployment previously: https://techcommunity.microsoft.com/t5/intune-customer-success/support-tip-how-to-configure-ndes-for-scep-certificate/ba-p/455125 Now I am getting this error on the clients: SCEP Certificate enrollment for Local system via https://xxxx.msappproxy.net/certsrv/mscep/mscep.dll/pkiclient.exe failed: PkiStatus(2): SCEPDispositionFailureFailInfo(2): SCEPFailBadRequestEnrollStatus(256): EnrollDeniedElement not found. 0x80070490 (WIN32: 1168 ERROR_NOT_FOUND)ProcessResponseMessageSubmit(Request): HTTP/1.1 200 Date: Thu, 01 Apr 2021 10:02:02 GMTContent-Length: 721Content-Type: application/x-pki-messageSet-Cookie: AzureAppProxyAnalyticCookie_2e4403a3-1918-4ce0-aaf2-e752fa9d6863_1.3=3|qzY7bL/WLLHXmlj5B8Ep9twHqojNPYrNavM/iOobspl+Ac1wt6jC9PqFstewofZ10P0u0moD2qwC6Dba20LXLxelotl9/MF0cD1ujohYNmnLj/jtn2w8hrhtms77R5zxnAGYT1icFIi1bLl9xtlX7g==; path=/; Secure; SameSite=Nonex-ms-proxy-app-id: 2e4403a3-1918-4ce0-aaf2-e752fa9d6863x-ms-proxy-group-id: 5e7fb653-6fe5-45c6-b365-4d39c87c6726x-ms-proxy-subscription-id: 064b53d9-40d8-4867-b493-2e949a06ed13x-ms-proxy-transaction-id: 3fa707f7-0ee5-4042-8f69-1a28c13b515ax-ms-proxy-service-name: proxy-appproxy-NEUR-DUB02P-2x-ms-proxy-data-center: NEURx-ms-proxy-connector-id: 54059fe0-81be-4023-9c48-1a6a9cd26374x-powered-by: ASP.NETNel: {"report_to":"network-errors","max_age":86400,"success_fraction":0.001,"failure_fraction":1.0}Report-To: {"group":"network-errors","max_age":86400,"endpoints":[{"url":"https://ffde.nelreports.net/api/report?cat=proxy-appproxy-NEUR-DUB02P-2"}]}Method: POST(3594ms)Stage: ProcessResponseMessageElement not found. 0x80070490 (WIN32: 1168 ERROR_NOT_FOUND) I've tried what I can find on Google but still not been able to resolve. Just wondering if I have missed anything obvious or if anyone has had similar issues Cheers
×
×
  • Create New...